In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
04 Apr 2022, 16:53
Type | Values Removed | Values Added |
---|---|---|
CPE |
31 Mar 2022, 17:37
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:apache:log4j:2.0:beta8:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.6.2:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:alpha2:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.5:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.4:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.4.1:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.6.1:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:rc2:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:alpha1:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:beta5:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:beta4:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:beta2:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.7:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0.1:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0.2:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.3:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:beta6:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.8.1:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.6:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.1:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:beta1:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:beta7:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.8:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:beta3:*:*:*:*:*:* cpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:* |
cpe:2.3:a:oracle:goldengate:12.3.2.1.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:instantis_enterprisetrack:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:utilities_advanced_spatial_and_operational_analytics:2.7.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:rapid_planning:12.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_network_integrity:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:identity_manager_connector:9.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:* cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_lending_and_leasing:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_regulatory_reporting_with_agilereporter:8.0.9.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:rapid_planning:12.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_extract_transform_and_load:19.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_service_backbone:15.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_service_backbone:16.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:in-memory_performance-driven_planning:12.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:in-memory_performance-driven_planning:12.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:soa_suite:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_advanced_inventory_planning:14.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:endeca_information_discovery_studio:3.2.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_service_backbone:14.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:4.0.1.0:*:*:*:*:*:*:* cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_advanced_inventory_planning:15.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_lending_and_leasing:12.5.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:timesten_in-memory_database:11.2.2.8.49:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_interactive_session_recorder:*:*:*:*:*:*:*:* |
References | (MLIST) https://lists.apache.org/thread.html/eea03d504b36e8f870e8321d908e1def1addda16adda04327fe7c125@%3Cdev.logging.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpujan2020.html - Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/ra38785cfc0e7f17f8e24bebf775dd032c033fadcaea29e5bc9fffc60@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r3a85514a518f3080ab1fc2652cfe122c2ccf67cfb32356acb1b08fe8@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r2ce8d26154bea939536e6cf27ed02d3192bf5c5d04df885a80fe89b3@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpuApr2021.html - Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r18f1c010b554a3a2d761e8ffffd8674fd4747bcbcf16c643d708318c@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/277b4b5c2b0e06a825ccec565fa65bd671f35a4d58e3e2ec5d0618e1@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rb1b29aee737e1c37fe1d48528cb0febac4f5deed51f5412e6fdfe2bf@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpujan2022.html - Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rca24a281000fb681d7e26e5c031a21eb4b0593a7735f781b53dae4e2@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rdbd579dc223f06af826d7de340218ee2f80d8b43fa7e4decb2a63f44@%3Cgithub.beam.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rbfa7a0742be4981a3f9356a23d0e1a5f2e1eabde32a1a3d8e41420f8@%3Cgithub.beam.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/raedd12dc24412b3780432bf202a2618a21a727788543e5337a458ead@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (N/A) https://www.oracle.com/security-alerts/cpuapr2020.html - Third Party Advisory | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2019/12/19/2Â - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/re8c21ed9dd218c217d242ffa90778428e446b082b5e1c29f567e8374@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r2ff63f210842a3c5e42f03a35d8f3a345134d073c80a04077341c211@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r0831e2e52a390758ce39a6193f82c11c295175adce6e6307de28c287@%3Cissues.beam.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/0dcca05274d20ef2d72584edcf8c917bbb13dbbd7eb35cae909d02e9@%3Cdev.logging.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MISC) https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html - Patch, Third Party Advisory | |
References | (MISC) https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html - Patch, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rdec0d8ac1f03e6905b0de2df1d5fcdb98b94556e4f6cccf7519fdb26@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r4b25538be50126194cc646836c718b1a4d8f71bd9c912af5b59134ad@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rc1eaed7f7d774d5d02f66e49baced31e04827a1293d61a70bd003ca7@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpujul2020.html - Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r3784834e80df2f284577a5596340fb84346c91a2dea6a073e65e3397@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r61590890edcc64140e0c606954b29a063c3d08a2b41d447256d51a78@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r746fbc3fc13aee292ae6851f7a5080f592fa3a67b983c6887cdb1fc5@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/ra9a682bc0a8dff1c5cefdef31c7c25f096d9121207cf2d74e2fc563d@%3Ccommits.logging.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/8ab32b4c9f1826f20add7c40be08909de9f58a89dc1de9c09953f5ac@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/44491fb9cc19acc901f7cff34acb7376619f15638439416e3e14761c@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/479471e6debd608c837b9815b76eab24676657d4444fcfd5ef96d6e6@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpuoct2020.html - Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rcbb79023a7c8494cb389cd3d95420fa9e0d531ece0b780b8c1f99422@%3Ccommits.doris.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r3d666e4e8905157f3c046d31398b04f2bfd4519e31f266de108c6919@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r681b4432d0605f327b68b9f8a42662993e699d04614de4851c35ffd1@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpuoct2021.html - Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r9d5c1b558a15d374bd5abd2d3ae3ca7e50e796a0efdcf91e9c5b4cdd@%3Cgithub.beam.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/84cc4266238e057b95eb95dfd8b29d46a2592e7672c12c92f68b2917@%3Cannounce.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpujan2021.html - Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/6114ce566200d76e3cc45c521a62c2c5a4eac15738248f58a99f622c@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/e8fb7d76a244ee997ba4b217d6171227f7c2521af8c7c5b16cba27bc@%3Cdev.logging.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (REDHAT) https://access.redhat.com/errata/RHSA-2019:1545Â - Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r7bcdc710857725c311b856c0b82cee6207178af5dcde1bd43d289826@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rf2567488cfc9212b42e34c6393cfa1c14e30e4838b98dda84d71041f@%3Cdev.tika.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r23369fd603eb6d62d3b883a0a28d12052dcbd1d6d531137124cd7f83@%3Cgithub.beam.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MISC) https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html - Patch, Third Party Advisory | |
References | (CONFIRM) http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html - Patch, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rd5dbeee4808c0f2b9b51479b50de3cc6adb1072c332a200d9107f13e@%3Cissues.activemq.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r94b5aae09c4bcff5d06cf641be17b00bd83ba7e10cad737bf16a1b8f@%3Cgithub.beam.apache.org%3EÂ - Mailing List, Third Party Advisory | |
References | (CONFIRM) https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html - Patch, Third Party Advisory |
07 Feb 2022, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
20 Oct 2021, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Jul 2021, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Jul 2021, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
14 Jun 2021, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
28 May 2021, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2017-04-17 21:59
Updated : 2024-02-04 19:11
NVD link : CVE-2017-5645
Mitre link : CVE-2017-5645
CVE.ORG link : CVE-2017-5645
JSON object : View
Products Affected
oracle
- retail_service_backbone
- fusion_middleware_mapviewer
- goldengate
- timesten_in-memory_database
- tape_library_acsls
- soa_suite
- peoplesoft_enterprise_fin_install
- communications_messaging_server
- communications_network_integrity
- policy_automation
- financial_services_analytical_applications_infrastructure
- identity_analytics
- autovue_vuelink_integration
- configuration_manager
- communications_interactive_session_recorder
- weblogic_server
- banking_platform
- communications_instant_messaging_server
- api_gateway
- retail_predictive_application_server
- enterprise_manager_for_mysql_database
- enterprise_manager_for_fusion_middleware
- policy_automation_connector_for_siebel
- insurance_calculation_engine
- instantis_enterprisetrack
- financial_services_profitability_management
- jd_edwards_enterpriseone_tools
- utilities_advanced_spatial_and_operational_analytics
- financial_services_hedge_management_and_ifrs_valuations
- enterprise_data_quality
- insurance_rules_palette
- siebel_ui_framework
- retail_extract_transform_and_load
- retail_open_commerce_platform
- rapid_planning
- enterprise_manager_base_platform
- jdeveloper
- communications_pricing_design_center
- application_testing_suite
- primavera_gateway
- in-memory_performance-driven_planning
- communications_webrtc_session_controller
- utilities_work_and_asset_management
- communications_service_broker
- enterprise_manager_for_peoplesoft
- identity_management_suite
- retail_advanced_inventory_planning
- financial_services_regulatory_reporting_with_agilereporter
- goldengate_application_adapters
- policy_automation_for_mobile_devices
- mysql_enterprise_monitor
- communications_online_mediation_controller
- financial_services_lending_and_leasing
- retail_clearance_optimization_engine
- bi_publisher
- communications_converged_application_server_-_service_controller
- flexcube_investor_servicing
- enterprise_manager_for_oracle_database
- endeca_information_discovery_studio
- retail_integration_bus
- financial_services_loan_loss_forecasting_and_provisioning
- financial_services_behavior_detection_platform
- insurance_policy_administration
- identity_manager_connector
netapp
- snapcenter
- oncommand_api_services
- oncommand_workflow_automation
- storage_automation_store
- service_level_manager
- oncommand_insight
redhat
- enterprise_linux_workstation
- enterprise_linux_server_tus
- enterprise_linux_desktop
- enterprise_linux_server_aus
- enterprise_linux_server_eus
- enterprise_linux
- fuse
- enterprise_linux_server
apache
- log4j
CWE
CWE-502
Deserialization of Untrusted Data