In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2017-04-17 14:59
Updated : 2022-04-04 09:53
NVD link : CVE-2017-5645
Mitre link : CVE-2017-5645
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
oracle
- siebel_ui_framework
- retail_integration_bus
- financial_services_regulatory_reporting_with_agilereporter
- policy_automation_for_mobile_devices
- soa_suite
- financial_services_profitability_management
- in-memory_performance-driven_planning
- application_testing_suite
- endeca_information_discovery_studio
- autovue_vuelink_integration
- financial_services_hedge_management_and_ifrs_valuations
- retail_predictive_application_server
- financial_services_analytical_applications_infrastructure
- enterprise_manager_for_fusion_middleware
- financial_services_loan_loss_forecasting_and_provisioning
- mysql_enterprise_monitor
- policy_automation
- weblogic_server
- communications_instant_messaging_server
- communications_converged_application_server_-_service_controller
- bi_publisher
- rapid_planning
- utilities_advanced_spatial_and_operational_analytics
- enterprise_manager_base_platform
- communications_interactive_session_recorder
- fusion_middleware_mapviewer
- jdeveloper
- enterprise_manager_for_mysql_database
- policy_automation_connector_for_siebel
- identity_analytics
- retail_extract_transform_and_load
- timesten_in-memory_database
- communications_messaging_server
- enterprise_manager_for_oracle_database
- utilities_work_and_asset_management
- enterprise_manager_for_peoplesoft
- retail_service_backbone
- api_gateway
- financial_services_behavior_detection_platform
- banking_platform
- communications_webrtc_session_controller
- communications_online_mediation_controller
- goldengate_application_adapters
- jd_edwards_enterpriseone_tools
- peoplesoft_enterprise_fin_install
- identity_management_suite
- enterprise_data_quality
- identity_manager_connector
- insurance_calculation_engine
- communications_service_broker
- retail_clearance_optimization_engine
- retail_advanced_inventory_planning
- financial_services_lending_and_leasing
- instantis_enterprisetrack
- retail_open_commerce_platform
- insurance_policy_administration
- insurance_rules_palette
- tape_library_acsls
- configuration_manager
- communications_network_integrity
- flexcube_investor_servicing
- primavera_gateway
- goldengate
- communications_pricing_design_center
netapp
- storage_automation_store
- service_level_manager
- oncommand_insight
- oncommand_workflow_automation
- snapcenter
- oncommand_api_services
redhat
- enterprise_linux
- enterprise_linux_server_aus
- enterprise_linux_workstation
- enterprise_linux_server_eus
- enterprise_linux_desktop
- enterprise_linux_server_tus
- fuse
- enterprise_linux_server
apache
- log4j