Vulnerability record · CVE-2021-4104 · published 14 December 2021
CVE-2021-4104: Apache Log4j 1.2 JMSAppender deserialization leads to remote code execution
Apache · Log4j
JMSAppender in Apache Log4j 1.2 deserializes untrusted data when an attacker can write to the Log4j configuration, allowing TopicBindingName and TopicConnectionFactoryBindingName to trigger JNDI lookups and remote code execution similar to CVE-2021-44228. It only affects Log4j 1.2 when JMSAppender is explicitly configured, which is not the default, and Log4j 1.2 has been end-of-life since August 2015. The flaw matters because many enterprise products still bundle Log4j 1.2, and successful exploitation gives code execution on the application server.
Description
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 3.1 score is 7.5 (HIGH) and EPSS is 0.81147, but exploitation requires prior write access to the Log4j configuration and JMSAppender is not enabled by default.
What it is
JMSAppender in Apache Log4j 1.2 deserializes untrusted data when an attacker can write to the Log4j configuration, allowing TopicBindingName and TopicConnectionFactoryBindingName to trigger JNDI lookups and remote code execution similar to CVE-2021-44228. It only affects Log4j 1.2 when JMSAppender is explicitly configured, which is not the default, and Log4j 1.2 has been end-of-life since August 2015. The flaw matters because many enterprise products still bundle Log4j 1.2, and successful exploitation gives code execution on the application server.
Impact
An attacker who can modify the Log4j configuration can cause the application to load and execute attacker-controlled code via JNDI, gaining remote code execution in the context of the logging process. This can lead to full compromise of the affected application and its host.
Attack surface
The vulnerability is network-reachable (AV:N) and requires low privileges (PR:L) because the attacker must already have write access to the Log4j configuration; no user interaction is needed (UI:N). It is only exposed when JMSAppender is explicitly enabled in the Log4j 1.2 configuration.
Exploitation
CVE-2021-4104 is not listed in CISA KEV, but EPSS shows a 30-day exploitation probability of 0.81147 (99.6th percentile), indicating high predicted likelihood. Reference tags are empty, so no confirmed in-the-wild exploitation is documented in this record.
What to do
- Upgrade from Log4j 1.2 to Log4j 2, which is the vendor-recommended fix and addresses this and other issues.
- If upgrade is not immediately possible, remove or disable JMSAppender in all Log4j 1.2 configurations.
- Restrict write access to Log4j configuration files to trusted administrators only.
- Apply vendor patches for affected products such as Red Hat JBoss, Oracle, and Fedora packages.
- Monitor and block outbound JNDI/LDAP/RMI traffic from application servers where feasible.
Detection
- Search application and server logs for JNDI lookup strings such as ldap://, rmi://, dns://, or suspicious TopicBindingName and TopicConnectionFactoryBindingName values.
- Monitor file integrity on Log4j configuration files for unauthorized changes.
- Detect unexpected outbound network connections from Java application servers to external LDAP, RMI, or DNS endpoints.
- Inventory applications and dependencies for Log4j 1.2 and JMSAppender usage.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
46 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-4104 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-4104), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.