vulnerability

Apache Log4j Core: CVE-2021-44228: JNDI support has not restricted what names could be resolved allowing remote code execution

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
01/07/2022
Added
02/04/2022
Modified
07/18/2022

Description

This detection identifies the presence of a vulnerable version of a vCenter Appliance stemming from CVE-2021-45046 (VMSA-2021-0028.9). Mitigation steps suggested by VMware outlined in KB87081.

Solution

vcenter-log4j-CVE-2021-44228
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.