{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "state": "PUBLISHED",
        "cveId": "CVE-2021-44228",
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "dateUpdated": "2025-10-21T23:25:23.121Z",
        "dateReserved": "2021-11-26T00:00:00.000Z",
        "datePublished": "2021-12-10T00:00:00.000Z"
    },
    "containers": {
        "cna": {
            "title": "Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints",
            "providerMetadata": {
                "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
                "shortName": "apache",
                "dateUpdated": "2023-04-03T00:00:00.000Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects."
                }
            ],
            "affected": [
                {
                    "vendor": "Apache Software Foundation",
                    "product": "Apache Log4j2",
                    "versions": [
                        {
                            "version": "2.0-beta9",
                            "status": "affected",
                            "lessThan": "log4j-core*",
                            "versionType": "custom",
                            "changes": [
                                {
                                    "at": "2.3.1",
                                    "status": "unaffected"
                                },
                                {
                                    "at": "2.4",
                                    "status": "affected"
                                },
                                {
                                    "at": "2.12.2",
                                    "status": "unaffected"
                                },
                                {
                                    "at": "2.13.0",
                                    "status": "affected"
                                },
                                {
                                    "at": "2.15.0",
                                    "status": "unaffected"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://logging.apache.org/log4j/2.x/security.html"
                },
                {
                    "name": "[oss-security] 20211210 CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints",
                    "tags": [
                        "mailing-list"
                    ],
                    "url": "http://www.openwall.com/lists/oss-security/2021/12/10/1"
                },
                {
                    "name": "[oss-security] 20211210 Re: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints",
                    "tags": [
                        "mailing-list"
                    ],
                    "url": "http://www.openwall.com/lists/oss-security/2021/12/10/2"
                },
                {
                    "name": "20211210 Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021",
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                },
                {
                    "name": "[oss-security] 20211210 Re: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints",
                    "tags": [
                        "mailing-list"
                    ],
                    "url": "http://www.openwall.com/lists/oss-security/2021/12/10/3"
                },
                {
                    "url": "https://security.netapp.com/advisory/ntap-20211210-0007/"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html"
                },
                {
                    "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032"
                },
                {
                    "url": "https://www.oracle.com/security-alerts/alert-cve-2021-44228.html"
                },
                {
                    "name": "DSA-5020",
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://www.debian.org/security/2021/dsa-5020"
                },
                {
                    "name": "[debian-lts-announce] 20211212 [SECURITY] [DLA 2842-1] apache-log4j2 security update",
                    "tags": [
                        "mailing-list"
                    ],
                    "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html"
                },
                {
                    "name": "FEDORA-2021-f0f501d01f",
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM/"
                },
                {
                    "name": "Microsoft’s Response to CVE-2021-44228 Apache Log4j 2",
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/"
                },
                {
                    "name": "[oss-security] 20211213 Re: CVE-2021-4104: Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2",
                    "tags": [
                        "mailing-list"
                    ],
                    "url": "http://www.openwall.com/lists/oss-security/2021/12/13/2"
                },
                {
                    "name": "[oss-security] 20211213 CVE-2021-4104: Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2",
                    "tags": [
                        "mailing-list"
                    ],
                    "url": "http://www.openwall.com/lists/oss-security/2021/12/13/1"
                },
                {
                    "name": "[oss-security] 20211214 CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack",
                    "tags": [
                        "mailing-list"
                    ],
                    "url": "http://www.openwall.com/lists/oss-security/2021/12/14/4"
                },
                {
                    "name": "20211210 A Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021",
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                },
                {
                    "name": "VU#930724",
                    "tags": [
                        "third-party-advisory"
                    ],
                    "url": "https://www.kb.cert.org/vuls/id/930724"
                },
                {
                    "url": "https://twitter.com/kurtseifried/status/1469345530182455296"
                },
                {
                    "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html"
                },
                {
                    "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html"
                },
                {
                    "name": "20211210 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021",
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                },
                {
                    "name": "[oss-security] 20211215 Re: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack",
                    "tags": [
                        "mailing-list"
                    ],
                    "url": "http://www.openwall.com/lists/oss-security/2021/12/15/3"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html"
                },
                {
                    "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf"
                },
                {
                    "name": "FEDORA-2021-66d6c484f3",
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB/"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html"
                },
                {
                    "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf"
                },
                {
                    "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf"
                },
                {
                    "url": "https://www.oracle.com/security-alerts/cpujan2022.html"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html"
                },
                {
                    "url": "https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html"
                },
                {
                    "url": "http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html"
                },
                {
                    "name": "20220314 APPLE-SA-2022-03-14-7 Xcode 13.3",
                    "tags": [
                        "mailing-list"
                    ],
                    "url": "http://seclists.org/fulldisclosure/2022/Mar/23"
                },
                {
                    "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001"
                },
                {
                    "url": "https://github.com/cisagov/log4j-affected-db"
                },
                {
                    "url": "https://support.apple.com/kb/HT213189"
                },
                {
                    "url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
                },
                {
                    "url": "https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228"
                },
                {
                    "url": "https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html"
                },
                {
                    "name": "20220721 Open-Xchange Security Advisory 2022-07-21",
                    "tags": [
                        "mailing-list"
                    ],
                    "url": "http://seclists.org/fulldisclosure/2022/Jul/11"
                },
                {
                    "url": "http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html"
                },
                {
                    "url": "http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html"
                },
                {
                    "name": "20221208 Intel Data Center Manager <= 5.1 Local Privileges Escalation",
                    "tags": [
                        "mailing-list"
                    ],
                    "url": "http://seclists.org/fulldisclosure/2022/Dec/2"
                },
                {
                    "url": "http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html"
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "This issue was discovered by Chen Zhaojun of Alibaba Cloud Security Team."
                }
            ],
            "metrics": [
                {
                    "other": {
                        "type": "unknown",
                        "content": {
                            "other": "critical"
                        }
                    }
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "type": "CWE",
                            "lang": "en",
                            "description": "CWE-502 Deserialization of Untrusted Data",
                            "cweId": "CWE-502"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "type": "CWE",
                            "lang": "en",
                            "description": "CWE-400 Uncontrolled Resource Consumption",
                            "cweId": "CWE-400"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "type": "CWE",
                            "lang": "en",
                            "description": "CWE-20 Improper Input Validation",
                            "cweId": "CWE-20"
                        }
                    ]
                }
            ],
            "x_generator": {
                "engine": "Vulnogram 0.0.9"
            },
            "source": {
                "discovery": "UNKNOWN"
            }
        },
        "adp": [
            {
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2024-08-04T04:17:24.696Z"
                },
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://logging.apache.org/log4j/2.x/security.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "name": "[oss-security] 20211210 CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints",
                        "tags": [
                            "mailing-list",
                            "x_transferred"
                        ],
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/10/1"
                    },
                    {
                        "name": "[oss-security] 20211210 Re: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints",
                        "tags": [
                            "mailing-list",
                            "x_transferred"
                        ],
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/10/2"
                    },
                    {
                        "name": "20211210 Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021",
                        "tags": [
                            "vendor-advisory",
                            "x_transferred"
                        ],
                        "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                    },
                    {
                        "name": "[oss-security] 20211210 Re: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints",
                        "tags": [
                            "mailing-list",
                            "x_transferred"
                        ],
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/10/3"
                    },
                    {
                        "url": "https://security.netapp.com/advisory/ntap-20211210-0007/",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://www.oracle.com/security-alerts/alert-cve-2021-44228.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "name": "DSA-5020",
                        "tags": [
                            "vendor-advisory",
                            "x_transferred"
                        ],
                        "url": "https://www.debian.org/security/2021/dsa-5020"
                    },
                    {
                        "name": "[debian-lts-announce] 20211212 [SECURITY] [DLA 2842-1] apache-log4j2 security update",
                        "tags": [
                            "mailing-list",
                            "x_transferred"
                        ],
                        "url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00007.html"
                    },
                    {
                        "name": "FEDORA-2021-f0f501d01f",
                        "tags": [
                            "vendor-advisory",
                            "x_transferred"
                        ],
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM/"
                    },
                    {
                        "name": "Microsoft’s Response to CVE-2021-44228 Apache Log4j 2",
                        "tags": [
                            "vendor-advisory",
                            "x_transferred"
                        ],
                        "url": "https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/"
                    },
                    {
                        "name": "[oss-security] 20211213 Re: CVE-2021-4104: Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2",
                        "tags": [
                            "mailing-list",
                            "x_transferred"
                        ],
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/13/2"
                    },
                    {
                        "name": "[oss-security] 20211213 CVE-2021-4104: Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2",
                        "tags": [
                            "mailing-list",
                            "x_transferred"
                        ],
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/13/1"
                    },
                    {
                        "name": "[oss-security] 20211214 CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack",
                        "tags": [
                            "mailing-list",
                            "x_transferred"
                        ],
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/14/4"
                    },
                    {
                        "name": "20211210 A Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021",
                        "tags": [
                            "vendor-advisory",
                            "x_transferred"
                        ],
                        "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                    },
                    {
                        "name": "VU#930724",
                        "tags": [
                            "third-party-advisory",
                            "x_transferred"
                        ],
                        "url": "https://www.kb.cert.org/vuls/id/930724"
                    },
                    {
                        "url": "https://twitter.com/kurtseifried/status/1469345530182455296",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdf",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "name": "20211210 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021",
                        "tags": [
                            "vendor-advisory",
                            "x_transferred"
                        ],
                        "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd"
                    },
                    {
                        "name": "[oss-security] 20211215 Re: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack",
                        "tags": [
                            "mailing-list",
                            "x_transferred"
                        ],
                        "url": "http://www.openwall.com/lists/oss-security/2021/12/15/3"
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdf",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "name": "FEDORA-2021-66d6c484f3",
                        "tags": [
                            "vendor-advisory",
                            "x_transferred"
                        ],
                        "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB/"
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdf",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://www.oracle.com/security-alerts/cpujan2022.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "name": "20220314 APPLE-SA-2022-03-14-7 Xcode 13.3",
                        "tags": [
                            "mailing-list",
                            "x_transferred"
                        ],
                        "url": "http://seclists.org/fulldisclosure/2022/Mar/23"
                    },
                    {
                        "url": "https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://github.com/cisagov/log4j-affected-db",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://support.apple.com/kb/HT213189",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://www.nu11secur1ty.com/2021/12/cve-2021-44228.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "name": "20220721 Open-Xchange Security Advisory 2022-07-21",
                        "tags": [
                            "mailing-list",
                            "x_transferred"
                        ],
                        "url": "http://seclists.org/fulldisclosure/2022/Jul/11"
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "name": "20221208 Intel Data Center Manager <= 5.1 Local Privileges Escalation",
                        "tags": [
                            "mailing-list",
                            "x_transferred"
                        ],
                        "url": "http://seclists.org/fulldisclosure/2022/Dec/2"
                    },
                    {
                        "url": "http://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html",
                        "tags": [
                            "x_transferred"
                        ]
                    }
                ]
            },
            {
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "CHANGED",
                            "version": "3.1",
                            "baseScore": 10,
                            "attackVector": "NETWORK",
                            "baseSeverity": "CRITICAL",
                            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                            "integrityImpact": "HIGH",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "NONE",
                            "confidentialityImpact": "HIGH"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2021-44228",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "active"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2025-02-04T14:25:34.416117Z"
                            }
                        }
                    },
                    {
                        "other": {
                            "type": "kev",
                            "content": {
                                "dateAdded": "2021-12-10",
                                "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44228"
                            }
                        }
                    }
                ],
                "references": [
                    {
                        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44228",
                        "tags": [
                            "government-resource"
                        ]
                    }
                ],
                "timeline": [
                    {
                        "time": "2021-12-10T00:00:00.000Z",
                        "lang": "en",
                        "value": "CVE-2021-44228 added to CISA KEV"
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-10-21T23:25:23.121Z"
                }
            }
        ]
    }
}