9.8

CVE-2019-17571

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheLog4j Version <= 1.2.17
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
CanonicalUbuntu Linux Version18.04 SwEditionlts
OpensuseLeap Version15.1
NetappOncommand System Manager Version >= 3.0 <= 3.1.3
OracleApplication Testing Suite Version13.3.0.1
OracleCommunications Network Integrity Version >= 7.3.2 <= 7.3.6
OracleFinancial Services Lending And Leasing Version >= 14.1.0 <= 14.8.0
OracleMysql Enterprise Monitor Version <= 8.0.29
OraclePrimavera Gateway Version >= 16.2 <= 16.2.11
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.7
OracleRapid Planning Version12.1
OracleRapid Planning Version12.2
OracleWeblogic Server Version10.3.6.0.0
OracleWeblogic Server Version12.1.3.0.0
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
ApacheBookkeeper Version < 4.14.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 53.46% 0.979
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://usn.ubuntu.com/4495-1/
Third Party Advisory