Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-23307


CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.


Published

2022-01-18T16:15:08.403

Last Modified

2024-11-21T06:48:22.733

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-502
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache chainsaw < 2.1.0 Yes
Application apache log4j < 2.0 Yes
Application qos reload4j < 1.2.18.1 Yes
Application oracle advanced_supply_chain_planning 12.1 Yes
Application oracle advanced_supply_chain_planning 12.2 Yes
Application oracle business_intelligence 5.9.0.0.0 Yes
Application oracle business_intelligence 12.2.1.3.0 Yes
Application oracle business_intelligence 12.2.1.4.0 Yes
Application oracle business_process_management_suite 12.2.1.3.0 Yes
Application oracle business_process_management_suite 12.2.1.4.0 Yes
Application oracle communications_eagle_ftp_table_base_retrieval 4.5 Yes
Application oracle communications_instant_messaging_server 10.0.1.5.0 Yes
Application oracle communications_messaging_server 8.1 Yes
Application oracle communications_network_integrity 7.3.6 Yes
Application oracle communications_offline_mediation_controller < 12.0.0.4.4 Yes
Application oracle communications_offline_mediation_controller 12.0.0.5.0 Yes
Application oracle communications_unified_inventory_management 7.4.1 Yes
Application oracle communications_unified_inventory_management 7.4.2 Yes
Application oracle e-business_suite_cloud_manager_and_cloud_backup_module < 2.2.1.1.1 Yes
Application oracle e-business_suite_cloud_manager_and_cloud_backup_module 2.2.1.1.1 Yes
Application oracle enterprise_manager_base_platform 13.4.0.0 Yes
Application oracle enterprise_manager_base_platform 13.5.0.0 Yes
Application oracle financial_services_revenue_management_and_billing_analytics 2.7.0.0 Yes
Application oracle financial_services_revenue_management_and_billing_analytics 2.7.0.1 Yes
Application oracle financial_services_revenue_management_and_billing_analytics 2.8.0.0 Yes
Application oracle healthcare_foundation 8.1.0 Yes
Application oracle hyperion_data_relationship_management < 11.2.8.0 Yes
Application oracle hyperion_infrastructure_technology < 11.2.8.0 Yes
Application oracle identity_management_suite 12.2.1.3.0 Yes
Application oracle identity_management_suite 12.2.1.4.0 Yes
Application oracle identity_manager_connector 11.1.1.5.0 Yes
Application oracle jdeveloper 12.2.1.3.0 Yes
Application oracle middleware_common_libraries_and_tools 12.2.1.4.0 Yes
Application oracle mysql_enterprise_monitor ≤ 8.0.29 Yes
Application oracle retail_extract_transform_and_load 13.2.5 Yes
Application oracle tuxedo 12.2.2.0.0 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes
Application oracle weblogic_server 12.2.1.4.0 Yes
Application oracle weblogic_server 14.1.1.0.0 Yes

References