Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33766
HistoryJan 19, 2022 - 12:47 p.m.

SQL Injection

2022-01-1912:47:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24

0.004 Low

EPSS

Percentile

74.9%

JDBCAppender in Log4j is vulnerable to SQL injection attacks. An attacker is able to execute arbitrary SQL commands via entering crafted strings into input fields and headers where the values to be inserted are converters from PatternLayout