CVE-2017-5645

Aliases:GHSA-fxph-q3j8-mv87
Advisory lineage Upstream: 0 Downstream: 13
Modified
Published: 17 Apr 2017, 21:00
Last modified:05 Aug 2024, 15:11

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
94.01% CRITICAL
94% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Apr 2017, 21:00
Published
Vulnerability first disclosed
05 Aug 2024, 15:11
Last Modified
Vulnerability information updated

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.0CRITICALScore: 9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 94.01% Percentile: 100%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • apache software foundationapache log4j

    All versions between 2.0-alpha1 and 2.8.1

  • apachelog4j

    ≥ 2.0, < 2.8.2

  • org.apache.logging.log4jlog4j

    ≥ 2.0, < 2.8.2

  • org.apache.logging.log4jlog4j-core

    ≥ 2.0, < 2.8.2

  • netapponcommand_api_services

    na

  • netapponcommand_insight

    na

  • netapponcommand_workflow_automation

    na

  • netappservice_level_manager

    na

  • netappsnapcenter

    na

  • netappstorage_automation_store

    na

  • oracleapi_gateway

    11.1.2.4.0

  • oracleapplication_testing_suite

    13.3.0.1

  • oracleautovue_vuelink_integration

    21.0.0 | 21.0.1

  • oraclebanking_platform

    2.6.0 | 2.6.1 | 2.6.2

  • oraclebi_publisher

    11.1.1.7.0 | 11.1.1.9.0 | 12.2.1.3.0 | 12.2.1.4.0

  • oraclecommunications_converged_application_server_-_service_controller

    6.1

  • oraclecommunications_instant_messaging_server

    10.0.1.3.0

  • oraclecommunications_interactive_session_recorder

    ≥ 6.0, ≤ 6.2

  • oraclecommunications_messaging_server

    < 8.0.2

  • oraclecommunications_network_integrity

    ≥ 7.3.2, ≤ 7.3.6

  • oraclecommunications_online_mediation_controller

    6.1

  • oraclecommunications_pricing_design_center

    11.1 | 12.0

  • oraclecommunications_service_broker

    6.0

  • oraclecommunications_webrtc_session_controller

    < 7.2

  • oracleconfiguration_manager

    12.1.2.0.2 | 12.1.2.0.5

  • oracleendeca_information_discovery_studio

    3.2.0

  • oracleenterprise_data_quality

    12.2.1.3.0

  • oracleenterprise_manager_base_platform

    12.1.0.5 | 13.2.0.0

  • oracleenterprise_manager_for_fusion_middleware

    12.1.0.5 | 13.2.0.0

  • oracleenterprise_manager_for_mysql_database

    ≤ 13.2.2.0.0

  • oracleenterprise_manager_for_oracle_database

    12.1.0.8 | 13.2.2

  • oracleenterprise_manager_for_peoplesoft

    13.1.1.1 | 13.2.1.1

  • oraclefinancial_services_analytical_applications_infrastructure

    ≥ 7.3.3.0.0, ≤ 7.3.3.0.2 | ≥ 8.0.0.0.0, ≤ 8.0.7.0.0

  • oraclefinancial_services_behavior_detection_platform

    ≥ 8.0.0.0.0, ≤ 8.0.4.0.0 | 6.1.1

  • oraclefinancial_services_hedge_management_and_ifrs_valuations

    8.0.4 | 8.0.5

  • oraclefinancial_services_lending_and_leasing

    ≥ 14.1.0, ≤ 14.8.0 | 12.5.0

  • oraclefinancial_services_loan_loss_forecasting_and_provisioning

    8.0.4 | 8.0.5

  • oraclefinancial_services_profitability_management

    ≥ 8.0.0.0.0, ≤ 8.0.7.0.0 | 6.1.1

  • oraclefinancial_services_regulatory_reporting_with_agilereporter

    8.0.9.2.0

  • oracleflexcube_investor_servicing

    12.0.4 | 12.1.0 | 12.3.0 | 12.4.0 | 14.0.0

  • oraclefusion_middleware_mapviewer

    12.2.1.2 | 12.2.1.3

  • oraclegoldengate

    12.3.2.1.1

  • oraclegoldengate_application_adapters

    12.3.2.1.1

  • oracleidentity_analytics

    11.1.1.5.8

  • oracleidentity_management_suite

    11.1.2.3.0 | 12.2.1.3.0

  • oracleidentity_manager_connector

    9.0

  • oraclein-memory_performance-driven_planning

    12.1 | 12.2

  • oracleinstantis_enterprisetrack

    ≥ 17.1, ≤ 17.3

  • oracleinsurance_calculation_engine

    10.1.1 | 10.2.1

  • oracleinsurance_policy_administration

    10.0 | 10.1 | 10.2 | 11.0

Showing first 50 affected entries in server-rendered view.

References (126)