CVE-2022-23302

Aliases:GHSA-w9p3-5cr8-m3jj
Modified
Published: 18 Jan 2022, 15:25
Last modified:27 May 2026, 13:46

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.8 HIGH
v3.1 (nvd)
EPSS Score
0.78% LOW
1% probability +0.14%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Jan 2022, 15:25
Published
Vulnerability first disclosed
27 May 2026, 13:46
Last Modified
Vulnerability information updated

Description

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

CVSS Metrics

  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6AV:N/AC:M/Au:S/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.78% Percentile: 74%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • apache software foundationapache log4j 1.x

    ≥ 1.0.1, < unspecified | ≥ unspecified, < 2.0-alpha1

  • apachelog4j

    ≥ 1.0.1, ≤ 1.2.17

  • broadcombrocade_sannav

    na

  • log4jlog4j

    ≤ 1.2.17

  • org.zenframework.z8.dependencies.commonslog4j-1.2.17

    ≤ 2.0

  • netappsnapmanager

    na

  • oracleadvanced_supply_chain_planning

    12.1 | 12.2

  • oraclebusiness_intelligence

    5.9.0.0.0 | 12.2.1.3.0 | 12.2.1.4.0

  • oraclebusiness_process_management_suite

    12.2.1.3.0 | 12.2.1.4.0

  • oraclecommunications_eagle_ftp_table_base_retrieval

    4.5

  • oraclecommunications_instant_messaging_server

    10.0.1.5.0

  • oraclecommunications_messaging_server

    8.1

  • oraclecommunications_network_integrity

    7.3.6

  • oraclecommunications_offline_mediation_controller

    < 12.0.0.4.4 | 12.0.0.5.0

  • oraclecommunications_unified_inventory_management

    7.4.1 | 7.4.2

  • oraclee-business_suite_cloud_manager_and_cloud_backup_module

    < 2.2.1.1.1 | 2.2.1.1.1

  • oracleenterprise_manager_base_platform

    13.4.0.0 | 13.5.0.0

  • oraclefinancial_services_revenue_management_and_billing_analytics

    2.7.0.0 | 2.7.0.1 | 2.8.0.0

  • oraclehealthcare_foundation

    8.1.0

  • oraclehyperion_data_relationship_management

    < 11.2.8.0

  • oraclehyperion_infrastructure_technology

    < 11.2.8.0

  • oracleidentity_management_suite

    12.2.1.3.0 | 12.2.1.4.0

  • oracleidentity_manager_connector

    11.1.1.5.0

  • oraclejdeveloper

    12.2.1.3.0

  • oraclemiddleware_common_libraries_and_tools

    12.2.1.4.0

  • oraclemysql_enterprise_monitor

    ≤ 8.0.29

  • oracletuxedo

    12.2.2.0.0

  • UnknownWebLogic Server

    12.2.1.3.0 | 12.2.1.4.0 | 14.1.1.0.0

  • qosreload4j

    < 1.2.18.1

References (11)