In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2017-04-17 21:59
Updated : 2022-02-07 16:15
NVD link : CVE-2017-5645
Mitre link : CVE-2017-5645
JSON object : View
Products Affected
oracle
- retail_predictive_application_server
- communications_messaging_server
- communications_pricing_design_center
- api_gateway
- identity_analytics
- soa_suite
- tape_library_acsls
- insurance_policy_administration
- mysql_enterprise_monitor
- financial_services_analytical_applications_infrastructure
- goldengate_application_adapters
- jdeveloper
- policy_automation_for_mobile_devices
- enterprise_manager_base_platform
- enterprise_manager_for_fusion_middleware
- retail_clearance_optimization_engine
- banking_platform
- utilities_work_and_asset_management
- financial_services_behavior_detection_platform
- insurance_rules_palette
- retail_extract_transform_and_load
- financial_services_loan_loss_forecasting_and_provisioning
- communications_converged_application_server_-_service_controller
- configuration_manager
- identity_management_suite
- policy_automation
- bi_publisher
- enterprise_data_quality
- financial_services_profitability_management
- jd_edwards_enterpriseone_tools
- financial_services_hedge_management_and_ifrs_valuations
- siebel_ui_framework
- autovue_vuelink_integration
- communications_webrtc_session_controller
- enterprise_manager_for_peoplesoft
- communications_service_broker
- retail_integration_bus
- policy_automation_connector_for_siebel
- enterprise_manager_for_mysql_database
- peoplesoft_enterprise_fin_install
- insurance_calculation_engine
- flexcube_investor_servicing
- fusion_middleware_mapviewer
- communications_online_mediation_controller
- enterprise_manager_for_oracle_database
- retail_open_commerce_platform
redhat
- enterprise_linux_desktop
- enterprise_linux_server_eus
- enterprise_linux
- enterprise_linux_server_tus
- enterprise_linux_server
- enterprise_linux_workstation
- enterprise_linux_server_aus
netapp
- storage_automation_store
- oncommand_api_services
- snapcenter
- oncommand_workflow_automation
- service_level_manager
- oncommand_insight
apache
- log4j
CWE
CWE-502
Deserialization of Untrusted Data
