← Vulnerability feed

Vulnerability record · CVE-2021-44832 · published 28 December 2021

CVE-2021-44832: Apache Log4j2 JDBC Appender JNDI LDAP Remote Code Execution

Apache · Log4j

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding 2.3.2 and 2.12.4) allow remote code execution when a configuration uses a JDBC Appender with a JNDI LDAP data source URI and the attacker controls the target LDAP server. The flaw is improper input validation of JNDI data source names, fixed by restricting them to the java protocol in 2.17.1, 2.12.4 and 2.3.2. It matters because it is another JNDI-based RCE path in the widely deployed Log4j2 library.

6.6 CVSS 3.1 Medium EPSS 98% · top 0.1% CWE-20 · Improper input validationCWE-74 · Injection
6.6CVSS 3.1 base score, v2 8.5
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
22Affected product versions listed by NVD
24References
17 Jun 2026Last modified by NVD

Description

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityAlthough CVSS is medium (6.6) and exploitation requires high privileges and attacker control of an LDAP server, the very high EPSS score and the severity of RCE in a ubiquitous logging library warrant high priority.

What it is

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding 2.3.2 and 2.12.4) allow remote code execution when a configuration uses a JDBC Appender with a JNDI LDAP data source URI and the attacker controls the target LDAP server. The flaw is improper input validation of JNDI data source names, fixed by restricting them to the java protocol in 2.17.1, 2.12.4 and 2.3.2. It matters because it is another JNDI-based RCE path in the widely deployed Log4j2 library.

Impact

An attacker who controls the referenced LDAP server can return a malicious JNDI reference and achieve remote code execution in the context of the Log4j2 process. This gives full compromise of the application's confidentiality, integrity and availability.

Attack surface

Reachable over the network (AV:N) but requires high attack complexity (AC:H) and high privileges (PR:H), with no user interaction (UI:N). The attacker must already control the LDAP server named in the JDBC Appender's JNDI data source URI, so exploitation depends on a specific non-default configuration and prior control of that server.

Exploitation

Not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is very high (0.97906, 99.9th percentile), indicating strong predicted exploitation activity. References include vendor patch and advisory tags from Apache, Oracle, Cisco, Debian, Fedora and Siemens.

What to do

  • Upgrade Log4j2 to 2.17.1, 2.12.4 or 2.3.2, which limit JNDI data source names to the java protocol.
  • If immediate upgrade is not possible, remove or disable JDBC Appenders that use JNDI LDAP data source URIs.
  • Restrict outbound LDAP traffic from application servers to only trusted, required destinations.
  • Audit Log4j2 configurations for JDBC Appender entries referencing ldap:// or other non-java JNDI URIs.
  • Apply vendor patches for downstream products (Oracle, Cisco, Debian, Fedora, Siemens) that bundle affected Log4j2 versions.

Detection

  • Search Log4j2 configuration files for JDBC Appender definitions containing JNDI data source URIs with ldap:// or non-java protocols.
  • Monitor application server outbound LDAP connections, especially to unexpected or external hosts.
  • Alert on JNDI lookup activity from Java processes that correlates with Log4j2 logging events.
  • Inventory Log4j2 versions across applications and flag any in the 2.0-beta7 to 2.17.0 range excluding 2.3.2 and 2.12.4.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

22 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2021/12/28/1 Mailing ListThird Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdf Third Party Advisory
https://issues.apache.org/jira/browse/LOG4J2-3293 Issue TrackingPatchVendor Advisory
https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143 Mailing ListVendor Advisory
https://lists.debian.org/debian-lts-announce/2021/12/msg00036.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHM
https://security.netapp.com/advisory/ntap-20220104-0001/ Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/12/28/1 Mailing ListThird Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-784507.pdf Third Party Advisory
https://issues.apache.org/jira/browse/LOG4J2-3293 Issue TrackingPatchVendor Advisory
https://lists.apache.org/thread/s1o5vlo78ypqxnzn6p8zf6t9shtq5143 Mailing ListVendor Advisory
https://lists.debian.org/debian-lts-announce/2021/12/msg00036.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVV25FXL4FU5X6X5BSL7RLQ
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T57MPJUW3MA6QGWZRTMCHHM
https://security.netapp.com/advisory/ntap-20220104-0001/ Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory

Track CVE-2021-44832 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-44832), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.