← Vulnerability feed

Vulnerability record · CVE-2022-23305 · published 18 January 2022

CVE-2022-23305: Log4j 1.x JDBCAppender SQL injection via logged input

Apache · Log4j

The JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m message converter are inserted without parameterization. An attacker who can place crafted strings into application input fields or headers that get logged can therefore inject SQL that the appender executes. It only applies when Log4j 1.x is explicitly configured to use JDBCAppender, which is not the default.

9.8 CVSS 3.1 Critical EPSS 67% · top 0.7% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 6.8
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
28Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCritical CVSS (9.8) and very high EPSS despite no KEV listing, but exploitation requires the non-default JDBCAppender configuration, which limits real-world exposure.

What it is

The JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m message converter are inserted without parameterization. An attacker who can place crafted strings into application input fields or headers that get logged can therefore inject SQL that the appender executes. It only applies when Log4j 1.x is explicitly configured to use JDBCAppender, which is not the default.

Impact

An attacker can execute unintended SQL queries through the logging path, potentially reading, modifying or destroying data in the database the appender writes to. The CVSS 3.1 vector rates confidentiality, integrity and availability impact all High.

Attack surface

Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) per the CVSS vector, by supplying crafted input that an application logs. It requires the target to run Log4j 1.x with JDBCAppender explicitly configured, so exposure is limited to those deployments.

Exploitation

Not listed in CISA KEV and no ransomware group is documented using it, but EPSS is high at 0.66537 (99.249th percentile), indicating elevated predicted exploitation activity. References are vendor advisories, mailing list posts and Oracle patch notices, with no public exploit tag.

What to do

  • Upgrade from end-of-life Log4j 1.2.x to Log4j 2, which re-introduced JDBCAppender with parameterized SQL support.
  • If upgrade is not immediately possible, remove or disable the JDBCAppender configuration and avoid logging untrusted input through it.
  • Apply vendor patches for affected downstream products (Oracle, NetApp and others listed in the advisories).
  • Validate and sanitize or encode untrusted values before they reach logging sinks that build SQL.
  • Inventory applications for Log4j 1.x and JDBCAppender usage to scope exposure.

Detection

  • Search application and logging configurations for JDBCAppender usage in Log4j 1.x deployments.
  • Monitor database logs for anomalous or unexpected SQL originating from the application's logging account.
  • Review logs for attacker-controlled fields containing SQL metacharacters such as quotes, comments or UNION keywords.
  • Alert on database errors or schema changes correlated with application log writes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-23305 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed9.0CVE-2021-45046Apache Log4j 2.15.0 Incomplete Fix Allows JNDI Lookup InjectionThe fix for CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. When a non-default Pattern Layout uses a Cont…KEVEPSS 100%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed7.5CVE-2020-14864Oracle Business Intelligence Enterprise Edition path traversal allows unauthenticated data accessOracle Business Intelligence Enterprise Edition contains a path traversal flaw in its Installation component affecting versions 5.5.0.0.0, 12.2.1.3.0…KEVEPSS 97%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.8CVE-2024-4173Broadcom brocade sannav information exposure vulnerabilityA vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various at…EPSS 0.59%9.8CVE-2024-29966Broadcom brocade sannav hard-coded credentials vulnerabilityBrocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vu…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2022-23305), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.