Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-08370
HistoryJan 20, 2022 - 12:00 a.m.

Apache Log4j SQL Injection Vulnerability

2022-01-2000:00:00
China National Vulnerability Database
www.cnvd.org.cn
24

0.004 Low

EPSS

Percentile

74.9%

Apache Log4j, a Java-based open source logging tool from the Apache Foundation, is vulnerable to SQL injection, which stems from a JDBCAppender in Log4j 1.2.x that accepts a SQL statement as a configuration parameter, where the value to be inserted is from the PatternLayout’s converter. The message converter \%m may always be included. An attacker could exploit this vulnerability to manipulate SQL by entering crafted strings into the input fields or headers of the logged application, allowing unexpected SQL queries to be executed.

CPENameOperatorVersion
Apache Log4j >=1.2,le1.2.17