Known vulnerabilities in Apache Foundation Apache Log4j

Website: https://www.apache.org
Total Security Bulletins: 14

Security bulletins (14)

Secuity bulletin Severity Status Published
SB2025122245: Missing TLS hostname verification in Apache Log4j Medium
Patched
22.12.2025
SB2023031040: Denial of service in Apache Log4j 1.x Medium
Patched
10.03.2023
SB2022042527: Multiple vulnerabilities in Oracle Retail Financial Integration Medium
Patched
25.04.2022
SB20220422113: Multiple vulnerabilities in Hyperion Data Relationship Management Medium
Patched
22.04.2022
SB2022011819: Deserialization of untrusted data in Apache Log4j Chainsaw component High
Patched
18.01.2022
SB2022011818: Multiple vulnerabilities in Apache Log4j High
Patched
18.01.2022
SB2021122816: Remote code execution via JDBC Appender in Apache Log4j Medium
Patched
28.12.2021
SB2021121802: Infinite recursion in Apache Log4j Medium
Patched
18.12.2021
SB2021121507: Insecure deserialization in Apache Log4j 1.2 Medium
Patched
15.12.2021
SB2021121504: Improper input validation in Apache Log4j High
Patched Exploited
15.12.2021
SB2021121003: Remote code execution in Apache Log4J Critical
Patched Exploited
10.12.2021
SB2020050406: Improper Certificate Validation in Apache Log4j Low
Patched
04.05.2020
SB2019122027: Remote code execution in Log4j Medium
Not patched
20.12.2019
SB2017040201: Remote code execution in Apache Log4 High
Patched
02.04.2017