Vulnerability record · CVE-2022-23305 · published 18 January 2022
CVE-2022-23305: Log4j 1.x JDBCAppender SQL injection via logged input
Apache · Log4j
The JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m message converter are inserted without parameterization. An attacker who can place crafted strings into application input fields or headers that get logged can therefore inject SQL that the appender executes. It only applies when Log4j 1.x is explicitly configured to use JDBCAppender, which is not the default.
Description
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS (9.8) and very high EPSS despite no KEV listing, but exploitation requires the non-default JDBCAppender configuration, which limits real-world exposure.
What it is
The JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m message converter are inserted without parameterization. An attacker who can place crafted strings into application input fields or headers that get logged can therefore inject SQL that the appender executes. It only applies when Log4j 1.x is explicitly configured to use JDBCAppender, which is not the default.
Impact
An attacker can execute unintended SQL queries through the logging path, potentially reading, modifying or destroying data in the database the appender writes to. The CVSS 3.1 vector rates confidentiality, integrity and availability impact all High.
Attack surface
Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) per the CVSS vector, by supplying crafted input that an application logs. It requires the target to run Log4j 1.x with JDBCAppender explicitly configured, so exposure is limited to those deployments.
Exploitation
Not listed in CISA KEV and no ransomware group is documented using it, but EPSS is high at 0.66537 (99.249th percentile), indicating elevated predicted exploitation activity. References are vendor advisories, mailing list posts and Oracle patch notices, with no public exploit tag.
What to do
- Upgrade from end-of-life Log4j 1.2.x to Log4j 2, which re-introduced JDBCAppender with parameterized SQL support.
- If upgrade is not immediately possible, remove or disable the JDBCAppender configuration and avoid logging untrusted input through it.
- Apply vendor patches for affected downstream products (Oracle, NetApp and others listed in the advisories).
- Validate and sanitize or encode untrusted values before they reach logging sinks that build SQL.
- Inventory applications for Log4j 1.x and JDBCAppender usage to scope exposure.
Detection
- Search application and logging configurations for JDBCAppender usage in Log4j 1.x deployments.
- Monitor database logs for anomalous or unexpected SQL originating from the application's logging account.
- Review logs for attacker-controlled fields containing SQL metacharacters such as quotes, comments or UNION keywords.
- Alert on database errors or schema changes correlated with application log writes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-23305 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23305), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.