Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-5645


In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.


Published

2017-04-17T21:59:00.373

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache log4j < 2.8.2 Yes
Application netapp oncommand_api_services - Yes
Application netapp oncommand_insight - Yes
Application netapp oncommand_workflow_automation - Yes
Application netapp service_level_manager - Yes
Application netapp snapcenter - Yes
Application netapp storage_automation_store - Yes
Application redhat fuse 1.0 Yes
Operating System redhat enterprise_linux 6.0 Yes
Operating System redhat enterprise_linux 6.7 Yes
Operating System redhat enterprise_linux 7.0 Yes
Operating System redhat enterprise_linux 7.3 Yes
Operating System redhat enterprise_linux 7.4 Yes
Operating System redhat enterprise_linux 7.5 Yes
Operating System redhat enterprise_linux 7.6 Yes
Operating System redhat enterprise_linux_desktop 7.0 Yes
Operating System redhat enterprise_linux_server 7.0 Yes
Operating System redhat enterprise_linux_server_aus 7.4 Yes
Operating System redhat enterprise_linux_server_aus 7.6 Yes
Operating System redhat enterprise_linux_server_eus 7.4 Yes
Operating System redhat enterprise_linux_server_eus 7.5 Yes
Operating System redhat enterprise_linux_server_eus 7.6 Yes
Operating System redhat enterprise_linux_server_tus 7.4 Yes
Operating System redhat enterprise_linux_server_tus 7.6 Yes
Operating System redhat enterprise_linux_workstation 7.0 Yes
Application oracle api_gateway 11.1.2.4.0 Yes
Application oracle application_testing_suite 13.3.0.1 Yes
Application oracle autovue_vuelink_integration 21.0.0 Yes
Application oracle autovue_vuelink_integration 21.0.1 Yes
Application oracle banking_platform 2.6.0 Yes
Application oracle banking_platform 2.6.1 Yes
Application oracle banking_platform 2.6.2 Yes
Application oracle bi_publisher 11.1.1.7.0 Yes
Application oracle bi_publisher 11.1.1.9.0 Yes
Application oracle bi_publisher 12.2.1.3.0 Yes
Application oracle bi_publisher 12.2.1.4.0 Yes
Application oracle communications_converged_application_server_-_service_controller 6.1 Yes
Application oracle communications_instant_messaging_server 10.0.1.3.0 Yes
Application oracle communications_interactive_session_recorder ≤ 6.2 Yes
Application oracle communications_messaging_server < 8.0.2 Yes
Application oracle communications_network_integrity ≤ 7.3.6 Yes
Application oracle communications_online_mediation_controller 6.1 Yes
Application oracle communications_pricing_design_center 11.1 Yes
Application oracle communications_pricing_design_center 12.0 Yes
Application oracle communications_service_broker 6.0 Yes
Application oracle communications_webrtc_session_controller < 7.2 Yes
Application oracle configuration_manager 12.1.2.0.2 Yes
Application oracle configuration_manager 12.1.2.0.5 Yes
Application oracle endeca_information_discovery_studio 3.2.0 Yes
Application oracle enterprise_data_quality 12.2.1.3.0 Yes
Application oracle enterprise_manager_base_platform 12.1.0.5 Yes
Application oracle enterprise_manager_base_platform 13.2.0.0 Yes
Application oracle enterprise_manager_for_fusion_middleware 12.1.0.5 Yes
Application oracle enterprise_manager_for_fusion_middleware 13.2.0.0 Yes
Application oracle enterprise_manager_for_mysql_database ≤ 13.2.2.0.0 Yes
Application oracle enterprise_manager_for_oracle_database 12.1.0.8 Yes
Application oracle enterprise_manager_for_oracle_database 13.2.2 Yes
Application oracle enterprise_manager_for_peoplesoft 13.1.1.1 Yes
Application oracle enterprise_manager_for_peoplesoft 13.2.1.1 Yes
Application oracle financial_services_analytical_applications_infrastructure ≤ 7.3.3.0.2 Yes
Application oracle financial_services_analytical_applications_infrastructure ≤ 8.0.7.0.0 Yes
Application oracle financial_services_behavior_detection_platform ≤ 8.0.4.0.0 Yes
Application oracle financial_services_behavior_detection_platform 6.1.1 Yes
Application oracle financial_services_hedge_management_and_ifrs_valuations 8.0.4 Yes
Application oracle financial_services_hedge_management_and_ifrs_valuations 8.0.5 Yes
Application oracle financial_services_lending_and_leasing ≤ 14.8.0 Yes
Application oracle financial_services_lending_and_leasing 12.5.0 Yes
Application oracle financial_services_loan_loss_forecasting_and_provisioning 8.0.4 Yes
Application oracle financial_services_loan_loss_forecasting_and_provisioning 8.0.5 Yes
Application oracle financial_services_profitability_management ≤ 8.0.7.0.0 Yes
Application oracle financial_services_profitability_management 6.1.1 Yes
Application oracle financial_services_regulatory_reporting_with_agilereporter 8.0.9.2.0 Yes
Application oracle flexcube_investor_servicing 12.0.4 Yes
Application oracle flexcube_investor_servicing 12.1.0 Yes
Application oracle flexcube_investor_servicing 12.3.0 Yes
Application oracle flexcube_investor_servicing 12.4.0 Yes
Application oracle flexcube_investor_servicing 14.0.0 Yes
Application oracle fusion_middleware_mapviewer 12.2.1.2 Yes
Application oracle fusion_middleware_mapviewer 12.2.1.3 Yes
Application oracle goldengate 12.3.2.1.1 Yes
Application oracle goldengate_application_adapters 12.3.2.1.1 Yes
Application oracle identity_analytics 11.1.1.5.8 Yes
Application oracle identity_management_suite 11.1.2.3.0 Yes
Application oracle identity_management_suite 12.2.1.3.0 Yes
Application oracle identity_manager_connector 9.0 Yes
Application oracle in-memory_performance-driven_planning 12.1 Yes
Application oracle in-memory_performance-driven_planning 12.2 Yes
Application oracle instantis_enterprisetrack ≤ 17.3 Yes
Application oracle insurance_calculation_engine 10.1.1 Yes
Application oracle insurance_calculation_engine 10.2.1 Yes
Application oracle insurance_policy_administration 10.0 Yes
Application oracle insurance_policy_administration 10.1 Yes
Application oracle insurance_policy_administration 10.2 Yes
Application oracle insurance_policy_administration 11.0 Yes
Application oracle insurance_rules_palette 10.0 Yes
Application oracle insurance_rules_palette 10.1 Yes
Application oracle insurance_rules_palette 10.2 Yes
Application oracle insurance_rules_palette 11.0 Yes
Application oracle insurance_rules_palette 11.1 Yes
Application oracle jd_edwards_enterpriseone_tools 4.0.1.0 Yes
Application oracle jd_edwards_enterpriseone_tools 9.2 Yes
Application oracle jdeveloper 11.1.1.9.0 Yes
Application oracle jdeveloper 12.1.3.0.0 Yes
Application oracle jdeveloper 12.2.1.3.0 Yes
Application oracle mysql_enterprise_monitor ≤ 3.4.7.4297 Yes
Application oracle mysql_enterprise_monitor ≤ 4.0.4.5235 Yes
Application oracle mysql_enterprise_monitor ≤ 8.0.0.8131 Yes
Application oracle peoplesoft_enterprise_fin_install 9.2 Yes
Application oracle policy_automation 10.4.7 Yes
Application oracle policy_automation 12.1.0 Yes
Application oracle policy_automation 12.1.1 Yes
Application oracle policy_automation 12.2.0 Yes
Application oracle policy_automation 12.2.1 Yes
Application oracle policy_automation 12.2.2 Yes
Application oracle policy_automation 12.2.3 Yes
Application oracle policy_automation 12.2.4 Yes
Application oracle policy_automation 12.2.5 Yes
Application oracle policy_automation 12.2.6 Yes
Application oracle policy_automation 12.2.7 Yes
Application oracle policy_automation 12.2.8 Yes
Application oracle policy_automation 12.2.9 Yes
Application oracle policy_automation 12.2.10 Yes
Application oracle policy_automation_connector_for_siebel 10.4.6 Yes
Application oracle policy_automation_for_mobile_devices 10.4.7 Yes
Application oracle policy_automation_for_mobile_devices 12.1.0 Yes
Application oracle policy_automation_for_mobile_devices 12.1.1 Yes
Application oracle policy_automation_for_mobile_devices 12.2.0 Yes
Application oracle policy_automation_for_mobile_devices 12.2.1 Yes
Application oracle policy_automation_for_mobile_devices 12.2.2 Yes
Application oracle policy_automation_for_mobile_devices 12.2.3 Yes
Application oracle policy_automation_for_mobile_devices 12.2.4 Yes
Application oracle policy_automation_for_mobile_devices 12.2.5 Yes
Application oracle policy_automation_for_mobile_devices 12.2.6 Yes
Application oracle policy_automation_for_mobile_devices 12.2.7 Yes
Application oracle policy_automation_for_mobile_devices 12.2.8 Yes
Application oracle policy_automation_for_mobile_devices 12.2.9 Yes
Application oracle policy_automation_for_mobile_devices 12.2.10 Yes
Application oracle primavera_gateway ≤ 16.2.11 Yes
Application oracle primavera_gateway ≤ 17.12.7 Yes
Application oracle rapid_planning 12.1 Yes
Application oracle rapid_planning 12.2 Yes
Application oracle retail_advanced_inventory_planning 14.0 Yes
Application oracle retail_advanced_inventory_planning 15.0 Yes
Application oracle retail_clearance_optimization_engine 14.0.5 Yes
Application oracle retail_extract_transform_and_load 13.0 Yes
Application oracle retail_extract_transform_and_load 13.1 Yes
Application oracle retail_extract_transform_and_load 13.2 Yes
Application oracle retail_extract_transform_and_load 19.0 Yes
Application oracle retail_integration_bus 14.0.0 Yes
Application oracle retail_integration_bus 14.1.0 Yes
Application oracle retail_integration_bus 15.0 Yes
Application oracle retail_integration_bus 16.0 Yes
Application oracle retail_open_commerce_platform 5.3.0 Yes
Application oracle retail_open_commerce_platform 6.0.0 Yes
Application oracle retail_open_commerce_platform 6.0.1 Yes
Application oracle retail_predictive_application_server 15.0.3 Yes
Application oracle retail_service_backbone 14.1 Yes
Application oracle retail_service_backbone 15.0 Yes
Application oracle retail_service_backbone 16.0 Yes
Application oracle siebel_ui_framework 18.7 Yes
Application oracle siebel_ui_framework 18.8 Yes
Application oracle siebel_ui_framework 18.9 Yes
Application oracle soa_suite 12.1.3.0.0 Yes
Application oracle soa_suite 12.2.1.3.0 Yes
Application oracle soa_suite 12.2.2.0.0 Yes
Application oracle tape_library_acsls 8.4 Yes
Application oracle timesten_in-memory_database 11.2.2.8.49 Yes
Application oracle utilities_advanced_spatial_and_operational_analytics 2.7.0.1 Yes
Application oracle utilities_work_and_asset_management 1.9.1.2.12 Yes
Application oracle weblogic_server 10.3.6.0.0 Yes
Application oracle weblogic_server 12.1.3.0.0 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes
Application oracle weblogic_server 12.2.1.4.0 Yes
Application oracle weblogic_server 14.1.1.0.0 Yes

References