CVE-2019-17571

Aliases:GHSA-2qrg-x229-3v8qRHSA-2022:5053DEBIAN-CVE-2019-17571CGA-c6jf-4p24-q6x3CGA-cvxf-2g8q-65h5CGA-gf6w-9c3q-h99mCGA-4947-j4fp-wqf5CGA-5pv2-cmcq-jv7xCGA-8f47-qcq6-q3w9CGA-9h9p-wwvp-x94wCGA-f2fv-rpr4-83vfCGA-m6mr-w7jw-xxhgCGA-q93g-vw7v-34jqCGA-w532-4v8f-442vCGA-wgv9-vj27-563f
Advisory lineage Upstream: 0 Downstream: 17
Modified
Published: 20 Dec 2019, 16:01
Last modified:28 May 2026, 18:30

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
69.06% CRITICAL
69% probability +20.61%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Dec 2019, 16:01
Published
Vulnerability first disclosed
28 May 2026, 18:30
Last Modified
Vulnerability information updated

Description

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 69.06% Percentile: 99%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • apache software foundationlog4j

    versions up to 1.2.17

  • apachebookkeeper

    < 4.14.3

  • apachelog4j

    ≤ 1.2.17

  • chainguarddruid

    all | < 35.0.1-r1

  • chainguardhadoop-fips-3.3.6

    all

  • chainguardhadoop-fips-3.4.2

    all

  • chainguardhadoop-fips-3.5

    all

  • wolfidruid

    all | < 35.0.1-r1

  • canonicalubuntu_linux

    18.04

  • debianapache-log4j1.2

    < 1.2.17-9 | < 1.2.17-9 | < 1.2.17-9 | < 1.2.17-9

  • debiandebian_linux

    8.0 | 9.0 | 10.0

  • log4jlog4j

    ≥ 1.2, ≤ 1.2.17

  • netapponcommand_system_manager

    ≥ 3.0, ≤ 3.1.3

  • netapponcommand_workflow_automation

    na

  • opensuseleap

    15.1

  • oracleapplication_testing_suite

    13.3.0.1

  • oraclecommunications_network_integrity

    ≥ 7.3.2, ≤ 7.3.6

  • oracleendeca_information_discovery_studio

    3.2.0

  • oraclefinancial_services_lending_and_leasing

    ≥ 14.1.0, ≤ 14.8.0 | 12.5.0

  • oraclemysql_enterprise_monitor

    ≤ 8.0.29

  • oracleprimavera_gateway

    ≥ 16.2, ≤ 16.2.11 | ≥ 17.12.0, ≤ 17.12.7

  • oraclerapid_planning

    12.1 | 12.2

  • oracleretail_extract_transform_and_load

    19.0

  • oracleretail_service_backbone

    14.1 | 15.0 | 16.0

  • oracleweblogic_server

    10.3.6.0.0 | 12.1.3.0.0 | 12.2.1.3.0 | 12.2.1.4.0 | 14.1.1.0.0

  • redhatlog4j

    < 0:1.2.14-6.7.el6_10

  • redhatlog4j-debuginfo

    < 0:1.2.14-6.7.el6_10

  • redhatlog4j-javadoc

    < 0:1.2.14-6.7.el6_10

  • redhatlog4j-manual

    < 0:1.2.14-6.7.el6_10

References (225)