9.8

CVE-2017-5645

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

Data is provided by the National Vulnerability Database (NVD)
ApacheLog4j Version >= 2.0 < 2.8.2
NetappOncommand Insight Version-
NetappSnapcenter Version-
RedhatFuse Version1.0
RedhatEnterprise Linux Version6.0
RedhatEnterprise Linux Version6.7
RedhatEnterprise Linux Version7.0
RedhatEnterprise Linux Version7.3
RedhatEnterprise Linux Version7.4
RedhatEnterprise Linux Version7.5
RedhatEnterprise Linux Version7.6
OracleApi Gateway Version11.1.2.4.0
OracleApplication Testing Suite Version13.3.0.1
OracleBanking Platform Version2.6.0
OracleBanking Platform Version2.6.1
OracleBanking Platform Version2.6.2
OracleBi Publisher Version11.1.1.7.0
OracleBi Publisher Version11.1.1.9.0
OracleBi Publisher Version12.2.1.3.0
OracleBi Publisher Version12.2.1.4.0
OracleCommunications Network Integrity Version >= 7.3.2 <= 7.3.6
OracleConfiguration Manager Version12.1.2.0.2
OracleConfiguration Manager Version12.1.2.0.5
OracleEnterprise Data Quality Version12.2.1.3.0
OracleFinancial Services Behavior Detection Platform Version >= 8.0.0.0.0 <= 8.0.4.0.0
OracleFinancial Services Lending And Leasing Version >= 14.1.0 <= 14.8.0
OracleFinancial Services Profitability Management Version >= 8.0.0.0.0 <= 8.0.7.0.0
OracleFusion Middleware Mapviewer Version12.2.1.2
OracleFusion Middleware Mapviewer Version12.2.1.3
OracleGoldengate Version12.3.2.1.1
OracleGoldengate Application Adapters Version12.3.2.1.1
OracleIdentity Analytics Version11.1.1.5.8
OracleIdentity Management Suite Version11.1.2.3.0
OracleIdentity Management Suite Version12.2.1.3.0
OracleInstantis Enterprisetrack Version >= 17.1 <= 17.3
OracleJdeveloper Version11.1.1.9.0
OracleJdeveloper Version12.1.3.0.0
OracleJdeveloper Version12.2.1.3.0
OracleMysql Enterprise Monitor Version >= 3.4.0.0 <= 3.4.7.4297
OracleMysql Enterprise Monitor Version >= 4.0.0.0 <= 4.0.4.5235
OracleMysql Enterprise Monitor Version >= 8.0.0.0.0 <= 8.0.0.8131
OraclePolicy Automation Version10.4.7
OraclePolicy Automation Version12.1.0
OraclePolicy Automation Version12.1.1
OraclePolicy Automation Version12.2.0
OraclePolicy Automation Version12.2.1
OraclePolicy Automation Version12.2.2
OraclePolicy Automation Version12.2.3
OraclePolicy Automation Version12.2.4
OraclePolicy Automation Version12.2.5
OraclePolicy Automation Version12.2.6
OraclePolicy Automation Version12.2.7
OraclePolicy Automation Version12.2.8
OraclePolicy Automation Version12.2.9
OraclePolicy Automation Version12.2.10
OraclePrimavera Gateway Version >= 16.2.0 <= 16.2.11
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.7
OracleRapid Planning Version12.1
OracleRapid Planning Version12.2
OracleRetail Integration Bus Version14.0.0
OracleRetail Integration Bus Version14.1.0
OracleRetail Integration Bus Version15.0
OracleRetail Integration Bus Version16.0
OracleSiebel Ui Framework Version18.7
OracleSiebel Ui Framework Version18.8
OracleSiebel Ui Framework Version18.9
OracleSoa Suite Version12.1.3.0.0
OracleSoa Suite Version12.2.1.3.0
OracleSoa Suite Version12.2.2.0.0
OracleTape Library Acsls Version8.4
OracleTimesten In-memory Database Version11.2.2.8.49
OracleWeblogic Server Version10.3.6.0.0
OracleWeblogic Server Version12.1.3.0.0
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 94.01% 0.999
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://www.securityfocus.com/bid/97702
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1040200
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1041294
Third Party Advisory
VDB Entry