Critical Vulnerability in Apache Log4j Java Logging Library
On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed:
For a description of this vulnerability, see the Log4j 2.15.0 section of the Apache Log4j Security Vulnerabilities page.
Low-Impact Vulnerability in Apache Log4j Java Logging Library
On December 14, 2021, the following low-impact vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was discovered:
For a description of this vulnerability, see the Log4j 2.12.2 and Log4j 2.16.0 section of the Apache Log4j Security Vulnerabilities page.
Cisco's Response to These Vulnerabilities
Cisco is assessing all products and services for impact from both CVE-2021-44228 and CVE-2021-45046. Product fixes will address both CVEs unless otherwise noted.
To help detect exploitation of these vulnerabilities, Cisco has released Snort rules at the following location: Talos Rules 2021-12-15
Update: As of December 16, 2021, Cisco will update this advisory as new information becomes available.
This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd