CVE-2021-44832: 
IBM Db2 脆弱性の分析と軽減

概要

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) were identified as vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. The vulnerability was discovered and disclosed on December 28, 2021 (Apache Mailing List).

技術的な詳細

The vulnerability allows remote code execution through JDBC Appender when configured with a JNDI LDAP data source URI. The issue received a CVSS v3.1 Base Score of 6.6 MEDIUM (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H) (NVD). The vulnerability specifically affects the JDBC Appender functionality when using JNDI LDAP data sources, requiring both configuration access and control of the target LDAP server to exploit.

影響

A successful exploitation of this vulnerability could allow an attacker with permission to modify the logging configuration file to execute arbitrary code through a malicious JDBC Appender configuration using JNDI LDAP data source URIs (Rapid7). This could lead to complete system compromise if successfully exploited.

エクスプロイト可能性

The vulnerability requires high privileges (ability to modify logging configuration) and high attack complexity to exploit, as the attacker needs both configuration access and control of the target LDAP server. The vulnerability has been assigned a 'moderate' severity rating (Apache Mailing List).

軽減策と回避策

The vulnerability was fixed in Log4j versions 2.17.1, 2.12.4, and 2.3.2 by limiting JNDI data source names to the java protocol (NVD). Organizations are strongly advised to upgrade to these patched versions. The issue is tracked as LOG4J2-3293 (Apache JIRA).

コミュニティの反応

Multiple vendors and organizations released security advisories and patches in response to this vulnerability, including Cisco, NetApp, Oracle, and Debian. Debian released security update DLA 2870-1 to address the vulnerability (Debian). Fedora also released updates for both version 34 and 35 to patch the vulnerability (Fedora).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 IBM Db2 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-87958HIGH8.1
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 10, 2026
CVE-2026-15955HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 14, 2026
CVE-2026-86093HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 10, 2026
CVE-2026-17463MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 14, 2026
CVE-2026-16702MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 14, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者