Vulnerability record · CVE-2021-44832 · published 28 December 2021
CVE-2021-44832: Apache Log4j2 JDBC Appender JNDI LDAP Remote Code Execution
Apache · Log4j
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding 2.3.2 and 2.12.4) allow remote code execution when a configuration uses a JDBC Appender with a JNDI LDAP data source URI and the attacker controls the target LDAP server. The flaw is improper input validation of JNDI data source names, fixed by restricting them to the java protocol in 2.17.1, 2.12.4 and 2.3.2. It matters because it is another JNDI-based RCE path in the widely deployed Log4j2 library.
Description
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityAlthough CVSS is medium (6.6) and exploitation requires high privileges and attacker control of an LDAP server, the very high EPSS score and the severity of RCE in a ubiquitous logging library warrant high priority.
What it is
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding 2.3.2 and 2.12.4) allow remote code execution when a configuration uses a JDBC Appender with a JNDI LDAP data source URI and the attacker controls the target LDAP server. The flaw is improper input validation of JNDI data source names, fixed by restricting them to the java protocol in 2.17.1, 2.12.4 and 2.3.2. It matters because it is another JNDI-based RCE path in the widely deployed Log4j2 library.
Impact
An attacker who controls the referenced LDAP server can return a malicious JNDI reference and achieve remote code execution in the context of the Log4j2 process. This gives full compromise of the application's confidentiality, integrity and availability.
Attack surface
Reachable over the network (AV:N) but requires high attack complexity (AC:H) and high privileges (PR:H), with no user interaction (UI:N). The attacker must already control the LDAP server named in the JDBC Appender's JNDI data source URI, so exploitation depends on a specific non-default configuration and prior control of that server.
Exploitation
Not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is very high (0.97906, 99.9th percentile), indicating strong predicted exploitation activity. References include vendor patch and advisory tags from Apache, Oracle, Cisco, Debian, Fedora and Siemens.
What to do
- Upgrade Log4j2 to 2.17.1, 2.12.4 or 2.3.2, which limit JNDI data source names to the java protocol.
- If immediate upgrade is not possible, remove or disable JDBC Appenders that use JNDI LDAP data source URIs.
- Restrict outbound LDAP traffic from application servers to only trusted, required destinations.
- Audit Log4j2 configurations for JDBC Appender entries referencing ldap:// or other non-java JNDI URIs.
- Apply vendor patches for downstream products (Oracle, Cisco, Debian, Fedora, Siemens) that bundle affected Log4j2 versions.
Detection
- Search Log4j2 configuration files for JDBC Appender definitions containing JNDI data source URIs with ldap:// or non-java protocols.
- Monitor application server outbound LDAP connections, especially to unexpected or external hosts.
- Alert on JNDI lookup activity from Java processes that correlates with Log4j2 logging events.
- Inventory Log4j2 versions across applications and flag any in the 2.0-beta7 to 2.17.0 range excluding 2.3.2 and 2.12.4.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
22 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-44832 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-44832), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.