CVE-2021-45105: 
IBM Db2 脆弱性の分析と軽減

概要

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. The vulnerability was discovered in December 2021 and fixed in Log4j versions 2.17.0, 2.12.3, and 2.3.1 (Apache Log4j).

技術的な詳細

The vulnerability occurs when the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}). Attackers with control over Thread Context Map (MDC) input data can craft malicious input data that contains a recursive lookup, resulting in a StackOverflowError that will terminate the process. The vulnerability has a CVSS v3.1 base score of 5.9 MEDIUM (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Only the log4j-core JAR file is impacted by this vulnerability (Apache Log4j, NVD).

影響

When successfully exploited, this vulnerability can lead to a denial of service (DoS) condition through uncontrolled recursion, causing the application to crash with a StackOverflowError. This affects the availability of systems using vulnerable Log4j versions (Apache Log4j).

エクスプロイト可能性

The vulnerability requires an attacker to have control over Thread Context Map (MDC) input data and the target system must be using a non-default Pattern Layout with Context Lookups. The attack complexity is considered high, but no authentication is required for remote exploitation (NVD).

軽減策と回避策

Users should upgrade to Log4j 2.3.1 (for Java 6), 2.12.3 (for Java 7), or 2.17.0 (for Java 8 and later). Alternatively, in PatternLayout configuration, replace Context Lookups like ${ctx:loginId} or $${ctx:loginId} with Thread Context Map patterns (%X, %mdc, or %MDC). Another option is to remove references to Context Lookups where they originate from external sources such as HTTP headers or user input (Apache Log4j).

コミュニティの反応

The vulnerability was independently discovered by multiple researchers including Hideki Okamoto of Akamai Technologies, Guy Lederfein of Trend Micro Research working with Trend Micro's Zero Day Initiative, and another anonymous vulnerability researcher. Major vendors like Cisco, Oracle, and VMware issued advisories and patches for their affected products (Apache Log4j).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 IBM Db2 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-87958HIGH8.1
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 10, 2026
CVE-2026-15955HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 14, 2026
CVE-2026-86093HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 10, 2026
CVE-2026-17463MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 14, 2026
CVE-2026-16702MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 14, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者