{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"important"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"text":"Copyright 2023 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"Security update for log4j","title":"Title of the patch"},{"category":"description","text":"This update for log4j fixes the following issue:\n\n- CVE-2021-4104: Disable the JMSAppender class from log4j to protect against\n  the log4jshell vulnerability. [bsc#1193662]\n","title":"Description of the patch"},{"category":"details","text":"SUSE-2021-4111,SUSE-SLE-Product-HPC-15-2021-4111,SUSE-SLE-Product-HPC-15-SP1-ESPOS-2021-4111,SUSE-SLE-Product-HPC-15-SP1-LTSS-2021-4111,SUSE-SLE-Product-SLES-15-2021-4111,SUSE-SLE-Product-SLES-15-SP1-BCL-2021-4111,SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-4111,SUSE-SLE-Product-SLES_SAP-15-2021-4111,SUSE-SLE-Product-SLES_SAP-15-SP1-2021-4111,SUSE-Storage-6-2021-4111","title":"Patchnames"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"self","summary":"URL for SUSE-SU-2021:4111-1","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20214111-1/"},{"category":"external","summary":"SUSE ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"self","summary":"URL of this CSAF notice","url":"https://ftp.suse.com/pub/projects/security/csaf/suse-su-2021_4111-1.json"},{"category":"self","summary":"E-Mail link for SUSE-SU-2021:4111-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2021-December/009917.html"},{"category":"self","summary":"SUSE Bug 1193662","url":"https://bugzilla.suse.com/1193662"},{"category":"self","summary":"SUSE CVE CVE-2021-4104 page","url":"https://www.suse.com/security/cve/CVE-2021-4104/"}],"title":"Security update for log4j","tracking":{"current_release_date":"2021-12-17T11:19:17Z","generator":{"date":"2021-12-17T11:19:17Z","engine":{"name":"cve-database.git:bin/generate-csaf.pl","version":"1"}},"id":"SUSE-SU-2021:4111-1","initial_release_date":"2021-12-17T11:19:17Z","revision_history":[{"date":"2021-12-17T11:19:17Z","number":"1","summary":"Current version"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version","name":"log4j-1.2.17-5.6.1.noarch","product":{"name":"log4j-1.2.17-5.6.1.noarch","product_id":"log4j-1.2.17-5.6.1.noarch"}},{"category":"product_version","name":"log4j-javadoc-1.2.17-5.6.1.noarch","product":{"name":"log4j-javadoc-1.2.17-5.6.1.noarch","product_id":"log4j-javadoc-1.2.17-5.6.1.noarch"}},{"category":"product_version","name":"log4j-manual-1.2.17-5.6.1.noarch","product":{"name":"log4j-manual-1.2.17-5.6.1.noarch","product_id":"log4j-manual-1.2.17-5.6.1.noarch"}},{"category":"product_version","name":"log4j-mini-1.2.17-5.6.1.noarch","product":{"name":"log4j-mini-1.2.17-5.6.1.noarch","product_id":"log4j-mini-1.2.17-5.6.1.noarch"}}],"category":"architecture","name":"noarch"},{"branches":[{"category":"product_name","name":"SUSE Linux Enterprise High Performance Computing 15-ESPOS","product":{"name":"SUSE Linux Enterprise High Performance Computing 15-ESPOS","product_id":"SUSE Linux Enterprise High Performance Computing 15-ESPOS","product_identification_helper":{"cpe":"cpe:/o:suse:sle_hpc-espos:15"}}},{"category":"product_name","name":"SUSE Linux Enterprise High Performance Computing 15-LTSS","product":{"name":"SUSE Linux Enterprise High Performance Computing 15-LTSS","product_id":"SUSE Linux Enterprise High Performance Computing 15-LTSS","product_identification_helper":{"cpe":"cpe:/o:suse:sle_hpc-ltss:15"}}},{"category":"product_name","name":"SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS","product":{"name":"SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS","product_identification_helper":{"cpe":"cpe:/o:suse:sle_hpc-espos:15:sp1"}}},{"category":"product_name","name":"SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS","product":{"name":"SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS","product_identification_helper":{"cpe":"cpe:/o:suse:sle_hpc-ltss:15:sp1"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 15-LTSS","product":{"name":"SUSE Linux Enterprise Server 15-LTSS","product_id":"SUSE Linux Enterprise Server 15-LTSS","product_identification_helper":{"cpe":"cpe:/o:suse:sles-ltss:15"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 15 SP1-BCL","product":{"name":"SUSE Linux Enterprise Server 15 SP1-BCL","product_id":"SUSE Linux Enterprise Server 15 SP1-BCL","product_identification_helper":{"cpe":"cpe:/o:suse:sles_bcl:15:sp1"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 15 SP1-LTSS","product":{"name":"SUSE Linux Enterprise Server 15 SP1-LTSS","product_id":"SUSE Linux Enterprise Server 15 SP1-LTSS","product_identification_helper":{"cpe":"cpe:/o:suse:sles-ltss:15:sp1"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server for SAP Applications 15","product":{"name":"SUSE Linux Enterprise Server for SAP Applications 15","product_id":"SUSE Linux Enterprise Server for SAP Applications 15","product_identification_helper":{"cpe":"cpe:/o:suse:sles_sap:15"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server for SAP Applications 15 SP1","product":{"name":"SUSE Linux Enterprise Server for SAP Applications 15 SP1","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP1","product_identification_helper":{"cpe":"cpe:/o:suse:sles_sap:15:sp1"}}},{"category":"product_name","name":"SUSE Enterprise Storage 6","product":{"name":"SUSE Enterprise Storage 6","product_id":"SUSE Enterprise Storage 6","product_identification_helper":{"cpe":"cpe:/o:suse:ses:6"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"log4j-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15-ESPOS","product_id":"SUSE Linux Enterprise High Performance Computing 15-ESPOS:log4j-1.2.17-5.6.1.noarch"},"product_reference":"log4j-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15-ESPOS"},{"category":"default_component_of","full_product_name":{"name":"log4j-manual-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15-ESPOS","product_id":"SUSE Linux Enterprise High Performance Computing 15-ESPOS:log4j-manual-1.2.17-5.6.1.noarch"},"product_reference":"log4j-manual-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15-ESPOS"},{"category":"default_component_of","full_product_name":{"name":"log4j-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15-LTSS","product_id":"SUSE Linux Enterprise High Performance Computing 15-LTSS:log4j-1.2.17-5.6.1.noarch"},"product_reference":"log4j-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15-LTSS"},{"category":"default_component_of","full_product_name":{"name":"log4j-manual-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15-LTSS","product_id":"SUSE Linux Enterprise High Performance Computing 15-LTSS:log4j-manual-1.2.17-5.6.1.noarch"},"product_reference":"log4j-manual-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15-LTSS"},{"category":"default_component_of","full_product_name":{"name":"log4j-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:log4j-1.2.17-5.6.1.noarch"},"product_reference":"log4j-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS"},{"category":"default_component_of","full_product_name":{"name":"log4j-manual-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:log4j-manual-1.2.17-5.6.1.noarch"},"product_reference":"log4j-manual-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS"},{"category":"default_component_of","full_product_name":{"name":"log4j-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:log4j-1.2.17-5.6.1.noarch"},"product_reference":"log4j-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS"},{"category":"default_component_of","full_product_name":{"name":"log4j-manual-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS","product_id":"SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:log4j-manual-1.2.17-5.6.1.noarch"},"product_reference":"log4j-manual-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS"},{"category":"default_component_of","full_product_name":{"name":"log4j-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise Server 15-LTSS","product_id":"SUSE Linux Enterprise Server 15-LTSS:log4j-1.2.17-5.6.1.noarch"},"product_reference":"log4j-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise Server 15-LTSS"},{"category":"default_component_of","full_product_name":{"name":"log4j-manual-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise Server 15-LTSS","product_id":"SUSE Linux Enterprise Server 15-LTSS:log4j-manual-1.2.17-5.6.1.noarch"},"product_reference":"log4j-manual-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise Server 15-LTSS"},{"category":"default_component_of","full_product_name":{"name":"log4j-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise Server 15 SP1-BCL","product_id":"SUSE Linux Enterprise Server 15 SP1-BCL:log4j-1.2.17-5.6.1.noarch"},"product_reference":"log4j-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP1-BCL"},{"category":"default_component_of","full_product_name":{"name":"log4j-manual-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise Server 15 SP1-BCL","product_id":"SUSE Linux Enterprise Server 15 SP1-BCL:log4j-manual-1.2.17-5.6.1.noarch"},"product_reference":"log4j-manual-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP1-BCL"},{"category":"default_component_of","full_product_name":{"name":"log4j-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise Server 15 SP1-LTSS","product_id":"SUSE Linux Enterprise Server 15 SP1-LTSS:log4j-1.2.17-5.6.1.noarch"},"product_reference":"log4j-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP1-LTSS"},{"category":"default_component_of","full_product_name":{"name":"log4j-manual-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise Server 15 SP1-LTSS","product_id":"SUSE Linux Enterprise Server 15 SP1-LTSS:log4j-manual-1.2.17-5.6.1.noarch"},"product_reference":"log4j-manual-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise Server 15 SP1-LTSS"},{"category":"default_component_of","full_product_name":{"name":"log4j-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 15","product_id":"SUSE Linux Enterprise Server for SAP Applications 15:log4j-1.2.17-5.6.1.noarch"},"product_reference":"log4j-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 15"},{"category":"default_component_of","full_product_name":{"name":"log4j-manual-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 15","product_id":"SUSE Linux Enterprise Server for SAP Applications 15:log4j-manual-1.2.17-5.6.1.noarch"},"product_reference":"log4j-manual-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 15"},{"category":"default_component_of","full_product_name":{"name":"log4j-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 15 SP1","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP1:log4j-1.2.17-5.6.1.noarch"},"product_reference":"log4j-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 15 SP1"},{"category":"default_component_of","full_product_name":{"name":"log4j-manual-1.2.17-5.6.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 15 SP1","product_id":"SUSE Linux Enterprise Server for SAP Applications 15 SP1:log4j-manual-1.2.17-5.6.1.noarch"},"product_reference":"log4j-manual-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Linux Enterprise Server for SAP Applications 15 SP1"},{"category":"default_component_of","full_product_name":{"name":"log4j-1.2.17-5.6.1.noarch as component of SUSE Enterprise Storage 6","product_id":"SUSE Enterprise Storage 6:log4j-1.2.17-5.6.1.noarch"},"product_reference":"log4j-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Enterprise Storage 6"},{"category":"default_component_of","full_product_name":{"name":"log4j-manual-1.2.17-5.6.1.noarch as component of SUSE Enterprise Storage 6","product_id":"SUSE Enterprise Storage 6:log4j-manual-1.2.17-5.6.1.noarch"},"product_reference":"log4j-manual-1.2.17-5.6.1.noarch","relates_to_product_reference":"SUSE Enterprise Storage 6"}]},"vulnerabilities":[{"cve":"CVE-2021-4104","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2021-4104"}],"notes":[{"category":"general","text":"JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.","title":"Vulnerability description"}],"product_status":{"fixed":["SUSE Enterprise Storage 6:log4j-1.2.17-5.6.1.noarch","SUSE Enterprise Storage 6:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-ESPOS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-ESPOS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-BCL:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-BCL:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15 SP1:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15 SP1:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15:log4j-manual-1.2.17-5.6.1.noarch"]},"references":[{"category":"external","summary":"CVE-2021-4104","url":"https://www.suse.com/security/cve/CVE-2021-4104"},{"category":"external","summary":"SUSE Bug 1193662 for CVE-2021-4104","url":"https://bugzilla.suse.com/1193662"},{"category":"external","summary":"SUSE Bug 1193978 for CVE-2021-4104","url":"https://bugzilla.suse.com/1193978"},{"category":"external","summary":"SUSE Bug 1194016 for CVE-2021-4104","url":"https://bugzilla.suse.com/1194016"},{"category":"external","summary":"SUSE Bug 1194842 for CVE-2021-4104","url":"https://bugzilla.suse.com/1194842"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["SUSE Enterprise Storage 6:log4j-1.2.17-5.6.1.noarch","SUSE Enterprise Storage 6:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-ESPOS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-ESPOS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-BCL:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-BCL:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15 SP1:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15 SP1:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15:log4j-manual-1.2.17-5.6.1.noarch"]}],"scores":[{"cvss_v3":{"baseScore":6.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["SUSE Enterprise Storage 6:log4j-1.2.17-5.6.1.noarch","SUSE Enterprise Storage 6:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-ESPOS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-ESPOS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise High Performance Computing 15-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-BCL:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-BCL:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15 SP1-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15-LTSS:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server 15-LTSS:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15 SP1:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15 SP1:log4j-manual-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15:log4j-1.2.17-5.6.1.noarch","SUSE Linux Enterprise Server for SAP Applications 15:log4j-manual-1.2.17-5.6.1.noarch"]}],"threats":[{"category":"impact","date":"2021-12-17T11:19:17Z","details":"moderate"}],"title":"CVE-2021-4104"}]}