CVE-2021-45046

Log4j Incomplete-Fix RCE: stopped at runtime

Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.

Published December 14, 2021 · Updated March 4, 2026

Mitigated by Waratek CRITICAL CVSS 9 v3.1 Actively exploited

The vulnerability

Remote code execution via Thread Context Map JNDI lookup

The 2.15.0 patch for Log4Shell (CVE-2021-44228) disabled the default JNDI lookup pattern but left non-default configurations exposed: when Pattern Layout uses a Context Lookup or a Thread Context Map pattern, attacker-controlled MDC input can still smuggle a JNDI lookup through and trigger remote code execution or information leakage.

Affected softwareApache Log4j 2 (log4j-core)
Affected versions2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, 2.3.1)
WeaknessJNDI injection / unsafe deserialization (CWE-917, CWE-502)
Published2021-12-14
SeverityCRITICAL · CVSS 9

Running an affected version? We can help.

Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.

Talk to us about protection

How Waratek RASP stops it

Blocked at runtime by Waratek RASP

Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.

Runtime, not perimeter

Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.

No code changes

Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.

Zero false positives

Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.

Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.

Common questions

Log4j Incomplete-Fix RCE FAQ

Is Log4j Incomplete-Fix RCE (CVE-2021-45046) exploitable?

CVE-2021-45046 carries a CVSS 9/10 (CRITICAL) rating and affects Apache Log4j 2 (log4j-core) 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, 2.3.1). The 2.15.0 patch for Log4Shell (CVE-2021-44228) disabled the default JNDI lookup pattern but left non-default configurations exposed: when Pattern Layout uses a Context Lookup or a Thread Context Map pattern, attacker-controlled MDC input can still smuggle a JNDI lookup through and trigger remote code execution or information leakage. It is listed in CISA's Known Exploited Vulnerabilities catalog, with known ransomware campaign use.

How does Waratek mitigate Log4j Incomplete-Fix RCE (CVE-2021-45046)?

Waratek RASP blocks exploitation of Log4j Incomplete-Fix RCE (CVE-2021-45046) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.

How quickly was Log4j Incomplete-Fix RCE (CVE-2021-45046) exploited after disclosure?

A working exploit for CVE-2021-45046 appeared within 2 days of its NVD disclosure, on December 15, 2021.

Protect your apps in production

Get protected against Log4j Incomplete-Fix RCE - without code changes or redeploying

Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2021-45046 and attacks like it, and get you covered in production.