8.8

CVE-2022-23302

Deserialization of untrusted data in JMSSink in Apache Log4j 1.x

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Log4j Version >= 1.0.1 <= 1.2.17
Netapp ≫ Snapmanager Version - SwPlatform oracle
Netapp ≫ Snapmanager Version - SwPlatform sap
Broadcom ≫ Brocade Sannav Version -
Qos ≫ Reload4j Version < 1.2.18.1
Oracle ≫ Business Intelligence Version 5.9.0.0.0 SwEdition enterprise
Oracle ≫ Business Intelligence Version 12.2.1.3.0 SwEdition enterprise
Oracle ≫ Business Intelligence Version 12.2.1.4.0 SwEdition enterprise
Oracle ≫ Business Process Management Suite Version 12.2.1.3.0
Oracle ≫ Business Process Management Suite Version 12.2.1.4.0
Oracle ≫ Healthcare Foundation Version 8.1.0
Oracle ≫ Identity Management Suite Version 12.2.1.3.0
Oracle ≫ Identity Management Suite Version 12.2.1.4.0
Oracle ≫ Identity Manager Connector Version 11.1.1.5.0
Oracle ≫ Jdeveloper Version 12.2.1.3.0
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.29
Oracle ≫ Tuxedo Version 12.2.2.0.0
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Oracle ≫ Weblogic Server Version 14.1.1.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 63.56% 0.991
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Patch
Third Party Advisory
http://www.openwall.com/lists/oss-security/2022/01/18/3
Third Party Advisory
Mailing List
https://lists.apache.org/thread/bsr3l5qz4g0myrjhy9h67bcxodpkwj4w
Vendor Advisory
Mailing List
Mitigation
https://logging.apache.org/log4j/1.2/index.html
Vendor Advisory
https://security.netapp.com/advisory/ntap-20220217-0006/
Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2022-23302-detect-log4j-1217-vulnerability
https://www.vicarius.io/vsociety/posts/cve-2022-23302-mitigate-log4j-1217-vulnerability