Apache Log4j Installation File Detected

high Web App Scanning Plugin ID 113076

Synopsis

Apache Log4j Installation File Detected

Description

Apache Log4j is an open source Java-based logging framework leveraged within numerous Java applications. The scanner detected the presence of installation files referring to the usage of Apache Log4j.

Solution

Detected files require an immediate review to verify the presence of Apache Log4j and if it is affected by the critical vulnerability described in CVE-2021-44228. If confirmed, update Log4j to version 2.15.0 or later or apply the vendor suggested mitigations. Finally, ensure that proper restrictions are in place on the detected file, or remove it if not required.

See Also

https://logging.apache.org/log4j/2.x/

Plugin Details

Severity: High

ID: 113076

Type: remote

Published: 12/14/2021

Updated: 12/14/2021

Scan Template: api, basic, full, log4shell, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: High

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Vulnerability Information

CPE: cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*

Reference Information