CVE-2019-17571

Aliases:GHSA-2qrg-x229-3v8q
Advisory lineage Upstream: 0 Downstream: 17
Modified
Published: 20 Dec 2019, 16:01
Last modified:28 May 2026, 18:30

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
28.5% HIGH
29% probability -19.95%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Dec 2019, 16:01
Published
Vulnerability first disclosed
28 May 2026, 18:30
Last Modified
Vulnerability information updated

Description

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 28.50% Percentile: 97%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • apache software foundationlog4j

    versions up to 1.2.17

  • apachebookkeeper

    < 4.14.3

  • apachelog4j

    ≤ 1.2.17

  • canonicalubuntu_linux

    18.04

  • debiandebian_linux

    8.0 | 9.0 | 10.0

  • log4jlog4j

    ≥ 1.2, ≤ 1.2.17

  • netapponcommand_system_manager

    ≥ 3.0, ≤ 3.1.3

  • netapponcommand_workflow_automation

    na

  • opensuseleap

    15.1

  • oracleapplication_testing_suite

    13.3.0.1

  • oraclecommunications_network_integrity

    ≥ 7.3.2, ≤ 7.3.6

  • oracleendeca_information_discovery_studio

    3.2.0

  • oraclefinancial_services_lending_and_leasing

    ≥ 14.1.0, ≤ 14.8.0 | 12.5.0

  • oraclemysql_enterprise_monitor

    ≤ 8.0.29

  • oracleprimavera_gateway

    ≥ 16.2, ≤ 16.2.11 | ≥ 17.12.0, ≤ 17.12.7

  • oraclerapid_planning

    12.1 | 12.2

  • oracleretail_extract_transform_and_load

    19.0

  • oracleretail_service_backbone

    14.1 | 15.0 | 16.0

  • UnknownWebLogic Server

    10.3.6.0.0 | 12.1.3.0.0 | 12.2.1.3.0 | 12.2.1.4.0 | 14.1.1.0.0

References (218)