# CVE-2021-45105 and CVE-2020-9488 vulnerabilities with java apm agent 1.28.4

**URL:** https://discuss.elastic.co/t/cve-2021-45105-and-cve-2020-9488-vulnerabilities-with-java-apm-agent-1-28-4/294766
**Category:** APM
**Tags:** java
**Created:** [January 19, 2022, 5:20am UTC](https://discuss.elastic.co/t/cve-2021-45105-and-cve-2020-9488-vulnerabilities-with-java-apm-agent-1-28-4/294766 "2022-01-19T05:20:49Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![felixbarny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felixbarny/32/27341_2.png) [@felixbarny](https://discuss.elastic.co/u/felixbarny)
#### Post date: [January 19, 2022, 7:10am UTC](https://discuss.elastic.co/t/cve-2021-45105-and-cve-2020-9488-vulnerabilities-with-java-apm-agent-1-28-4/294766/3 "2022-01-19T07:10:52Z")

</div>

Log4j 2.12.4, which is used in the Elastic APM Java Agent 1.28.4 addresses these vulnerabilities.

See also [Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31](https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476#apm-java-agent-announcement-esa-2021-31-21) and [Log4j – Apache Log4j Security Vulnerabilities](https://logging.apache.org/log4j/2.x/security.html).

If your vulnerability scanner doesn't detect that Log4j 2.12.4/Elastic APM Java Agent 1.28.4 contains fixes to these CVEs, please get in touch with the vendor of this scanner so that they can update their policies.

---

_[View the full topic](https://discuss.elastic.co/t/cve-2021-45105-and-cve-2020-9488-vulnerabilities-with-java-apm-agent-1-28-4/294766)._
