Broadcom Enterprise Software Security Advisory for Log4j 2 CVE-2021-44228 Vulnerability

Automation Analytics & Intelligence

34 more products


23 March 2022

10 December 2021




Security Advisory for Log4j 2 CVE-2021-44228 vulnerability

Issued: December 10th, 2021
Updated: March 23rd, 2022

Broadcom Software has investigated multiple Apache Log4j 2 vulnerabilities that were recently reported to Apache.  CVE identifiers CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-4104 have been assigned to these vulnerabilities.  These vulnerabilities have a cumulative Critical risk rating, and exploit code is in the wild.  The Log4j team has addressed these vulnerabilities in Log4j 2.16.0.

Log4j Versions Affected: All versions from 2.0-beta9 to 2.16.0

Note that CVE-2021-4104 affects only Log4j 1.2, and does not impact the Log4j 2.x branch.

CVE-2021-44228 Description: Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVE-2021-45046 Description: It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup or a Thread Context Map pattern to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

CVE-2021-45105 Description: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0 and 2.12.3.

CVE-2021-4104 Description: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

We have investigated the impact to each product and published fixes for all affected products as of 2021-12-30.  In addition to checking this advisory for updates, customers can check individual product support pages for updates, or open a support case.

Risk Rating

CVE-2021-44228 - Critical
Base CVSS Score: 10.0
Vector String - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2021-45046 - Critical
Base CVSS Score: 9.0
Vector String - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2021-45105 - High
Base CVSS Score: 7.5
Vector String - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2021-4104 - High
Base CVSS Score: 8.1
Vector String - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products and Components

App Synthetic Monitor (ASM)
Application Delivery Analysis
Application Test
Automation Intelligence
Automic Applications Manager
Automic Continuous Delivery Automation
Automic One Automation
Automic Workload Automation
CA Productivity Accelerator
Client Automation
DX App Experience Analytics (AxA)
DX NetOps
DX NetOps Performance Management (DA/DC/DR/OI Connector)
DX NetOps Spectrum
DX Operational Intelligence
IT Asset Manager
IT Asset Manager Asset Portfolio Management
NIM (Normalized Integration Management)
Rally Adapter for Jira
Service Catalog
Service Desk Manager
Service Management
Service Management - Asset Portfolio Management
Service Operations Insight (SOI)
Service Virtualization
Unified Infrastructure Management (UIM)

Non-Affected Products and Components

Agile Central (Rally) SaaS and OnPrem
Agile Requirements Designer (ARD)
Application Performance Management (APM), APM SaaS
Business Service Insight
Dollar Universe
Capacity Manager
Common Agents
Configuration Automation
Continuous Delivery Director
Continuous Delivery Director SAAS
DX NetOps Mediation Manager
DX NetOps Network Flow Analysis
DX NetOps Performance Management Portal, DA Proxy
DX NetOps Virtual Network Assurance
IT Process Automation
Mobile Device Manager
Nolio Release Automation
Software Change Manager (Harvest SCM)
Systems Performance for Infrastructure Managers (SPIM)
Test Data Manager
Unified Communications Monitor
Unified Self Service (USS)
Virtual Assurance for Infrastructure Managers (VAIM)
Workload Automation AE - Business Agents (AutoSys)
Workload Automation AE - Scheduler (AutoSys)
Workload Automation AE - System Agent (AutoSys)
Workload Automation Agents
Workload Automation IXP

Solutions, Workarounds, KB Articles
(for both affected and non-affected products)

Note that solutions, workarounds, and KB articles for affected products will be provided as they are approved by each product team.


Agile Central (Rally) SaaS and OnPrem:

Agile Requirements Designer (ARD):

App Synthetic Monitor (ASM):
Security Advisory: CVE-2021-44228 - Log4j Vulnerability and Broadcom CA App Synthetic Monitor (ASM)

Application Delivery Analysis: 

Application Performance Management (APM), APM SaaS:
Security Advisory: CVE-2021-44228 - log4j vulnerability and Broadcom CA APM
Security Advisory: CVE-2019-17571 and CVE-2021-4104 log4j 1.2 vulnerability and Broadcom CA APM

Application Test:

Automation Intelligence:

Automic Applications Manager:

Automic Continuous Delivery Automation:

Automic One Automation:

Automic Workload Automation:

Business Service Insight:


Capacity Manager:


CA Productivity Accelerator:

Clarity SaaS and Clarity On Premise:

Client Automation:

Common Agents:

Configuration Automation:

Continuous Delivery Director
Continuous Delivery Director SAAS


Dollar Universe:

DX App Experience Analytics (AXA):
CVE-2021-44228 & CVE-2021-45046: DX App Experience Analytics - Log4j vulnerability

DX NetOps (Spectrum, Performance Management (CAPM), Virtual Network Assurance (VNA), Mediation Manager (MM) and Network Flow Analysis (NFA)):

DX Operational Intelligence:


IT Asset Manager
IT Asset Manager Asset Portfolio Management
Service Management - Asset Portfolio Management

IT Process Automation:

NIM (Normalized Integration Management):

Nolio Release Automation:


Rally Adapter for Jira:

Service Catalog:

Service Desk Manager
Service Management - xFlow
Service Management - Jasper

Service Operations Insight (SOI):

Service Virtualization:

Software Change Manager (Harvest SCM):

Systems Performance for Infrastructure Managers (SPIM):

Test Data Manager:

Unified Communications Monitor:

Unified Infrastructure Management (UIM):

Unified Self Service (USS):

Virtual Assurance for Infrastructure Managers (VAIM):

Workload Automation AE - Business Agents (AutoSys)
Workload Automation AE - Scheduler (AutoSys)
Workload Automation AE - System Agent (AutoSys)
Workload Automation Agents
Workload Automation IXP


Apache Log4j 2:
Apache Log4j Security Vulnerabilities:
CISA Apache Log4j Vulnerability Guidance:

Change History

Version 1.0: 2021-12-10 - Initial Release
Version 1.1: 2021-12-11 0200 CT - Products, Solutions, Workarounds, KBs added
Version 1.2: 2021-12-11 0900 CT - More Products, Solutions, Workarounds, KBs added
Version 1.3: 2021-12-11 1000 CT - More updates
Version 1.4: 2021-12-11 1315 CT - More updates
Version 1.5: 2021-12-11 1330 CT - SDM and APM updates
Version 1.6: 2021-12-11 1600 CT - APM KB link, formatting
Version 1.7: 2021-12-11 1830 CT - dSeries
Version 2.0: 2021-12-11 2030 CT - Added SM – Japser; changed formatting
Version 2.1: 2021-12-12 1015 CT - Added UCM KB, UIM KB, SDM xFlow KB
Version 2.2: 2021-12-12 2230 CT - Added ADA KB
Version 2.3: 2021-12-13 0100 CT - Added USS
Version 2.4: 2021-12-13 0900 CT - Added USS KB, Sysload, Clarity update
Version 2.5: 2021-12-13 0945 CT - Added AXA update
Version 2.6: 2021-12-13 1115 CT - Added CAPKI KB
Version 2.7: 2021-12-13 1115 CT - Added NIM KB
Version 2.8: 2021-12-13 1245 CT - Added Rally SaaS and OnPrem
Version 2.9: 2021-12-13 1615 CT - DX NetOps updates and consolidations; multiple dependency KBs added
Version 3.0: 2021-12-14 0900 CT - Added VAIM, SPIM
Version 3.1: 2021-12-14 1030 CT - Added DX NetOps updates
Version 3.2: 2021-12-14 1100 CT - Added DX OI update
Version 3.3: 2021-12-14 1250 CT - Added Agile Central (Rally) KB; CISA reference
Version 3.4: 2021-12-14 1615 CT - Added ASM
Version 4.0: 2021-12-15 1015 CT - Added CVE-2021-45046 and CVE-2021-4104
Version 4.1: 2021-12-15 1815 CT - Added DX AxA, ASM advisory, APM advisory, AxA advisory, Workload Automation KBs
Version 4.2: 2021-12-16 0930 CT - Updated CVE descriptions, Service Virtualization KB is updated with patch, Clarity KB updated
Version 4.3: 2021-12-17 1050 CT - Updated CVSS for 4104 and 45046, updated affected log4j versions, added Rally Adapter for Jira
Version 4.4: 2021-12-18 0620 CT - Added CVE-2021-45105
Version 4.5: 2021-12-23 1045 CT - Updated APM, Service Virtualization, Automic One Automation, CVE-2021-45046 description, CVE-2021-45105 description
Version 5.0: 2022-01-09 2100 CT - Updated to note that fixes for all affected products were published by 2021-12-30.
Version 5.1: 2022-03-23 1200 CT - Added CA Productivity Accelerator

Broadcom Software customers may receive product alerts and advisories by subscribing to Proactive Notifications.

Customers who require additional information about this notice may contact Broadcom Software Support at

To report a suspected vulnerability in a CA Technologies product, please send a summary to the CA Technologies Product Vulnerability Response Team.

Copyright © 2022 Broadcom. All Rights Reserved. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries. Broadcom, the pulse logo, Connecting everything, CA Technologies and the CA technologies logo are among the trademarks of Broadcom. All trademarks, trade names, service marks and logos referenced herein belong to their respective companies.