In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2017-04-17 21:59
Updated : 2022-02-07 16:15
NVD link : CVE-2017-5645
Mitre link : CVE-2017-5645
JSON object : View
Products Affected
netapp
- service_level_manager
- oncommand_api_services
- storage_automation_store
- oncommand_insight
- snapcenter
- oncommand_workflow_automation
apache
- log4j
redhat
- enterprise_linux_server
- enterprise_linux_desktop
- enterprise_linux_workstation
- enterprise_linux_server_aus
- enterprise_linux_server_tus
- enterprise_linux_server_eus
- enterprise_linux
oracle
- peoplesoft_enterprise_fin_install
- financial_services_loan_loss_forecasting_and_provisioning
- communications_converged_application_server_-_service_controller
- siebel_ui_framework
- tape_library_acsls
- retail_clearance_optimization_engine
- retail_predictive_application_server
- retail_open_commerce_platform
- financial_services_analytical_applications_infrastructure
- financial_services_hedge_management_and_ifrs_valuations
- jd_edwards_enterpriseone_tools
- enterprise_manager_base_platform
- policy_automation_for_mobile_devices
- enterprise_manager_for_fusion_middleware
- goldengate_application_adapters
- soa_suite
- insurance_policy_administration
- identity_management_suite
- autovue_vuelink_integration
- insurance_calculation_engine
- enterprise_manager_for_peoplesoft
- policy_automation_connector_for_siebel
- api_gateway
- financial_services_profitability_management
- communications_webrtc_session_controller
- retail_extract_transform_and_load
- configuration_manager
- bi_publisher
- communications_messaging_server
- mysql_enterprise_monitor
- jdeveloper
- identity_analytics
- retail_integration_bus
- insurance_rules_palette
- financial_services_behavior_detection_platform
- policy_automation
- enterprise_manager_for_mysql_database
- communications_service_broker
- banking_platform
- communications_online_mediation_controller
- fusion_middleware_mapviewer
- enterprise_data_quality
- enterprise_manager_for_oracle_database
- communications_pricing_design_center
- flexcube_investor_servicing
- utilities_work_and_asset_management
CWE
CWE-502
Deserialization of Untrusted Data
