8.8
CVE-2022-23302
- EPSS 63.56%
- Veröffentlicht 18.01.2022 16:15:08
- Zuletzt bearbeitet 07.07.2025 18:15:24
- Erkennungen
Deserialization of untrusted data in JMSSink in Apache Log4j 1.x
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ Snapmanager Version - SwPlatform oracle
Netapp ≫ Snapmanager Version - SwPlatform sap
Broadcom ≫ Brocade Sannav Version -
Oracle ≫ Advanced Supply Chain Planning Version 12.1
Oracle ≫ Advanced Supply Chain Planning Version 12.2
Oracle ≫ Business Intelligence Version 5.9.0.0.0 SwEdition enterprise
Oracle ≫ Business Intelligence Version 12.2.1.3.0 SwEdition enterprise
Oracle ≫ Business Intelligence Version 12.2.1.4.0 SwEdition enterprise
Oracle ≫ Business Process Management Suite Version 12.2.1.3.0
Oracle ≫ Business Process Management Suite Version 12.2.1.4.0
Oracle ≫ Communications Eagle Ftp Table Base Retrieval Version 4.5
Oracle ≫ Communications Instant Messaging Server Version 10.0.1.5.0
Oracle ≫ Communications Messaging Server Version 8.1
Oracle ≫ Communications Network Integrity Version 7.3.6
Oracle ≫ Communications Offline Mediation Controller Version < 12.0.0.4.4
Oracle ≫ Communications Offline Mediation Controller Version 12.0.0.5.0
Oracle ≫ Communications Unified Inventory Management Version 7.4.1
Oracle ≫ Communications Unified Inventory Management Version 7.4.2
Oracle ≫ E-business Suite Cloud Manager And Cloud Backup Module Version < 2.2.1.1.1
Oracle ≫ E-business Suite Cloud Manager And Cloud Backup Module Version 2.2.1.1.1
Oracle ≫ Enterprise Manager Base Platform Version 13.4.0.0
Oracle ≫ Enterprise Manager Base Platform Version 13.5.0.0
Oracle ≫ Financial Services Revenue Management And Billing Analytics Version 2.7.0.0
Oracle ≫ Financial Services Revenue Management And Billing Analytics Version 2.7.0.1
Oracle ≫ Financial Services Revenue Management And Billing Analytics Version 2.8.0.0
Oracle ≫ Healthcare Foundation Version 8.1.0
Oracle ≫ Hyperion Data Relationship Management Version < 11.2.8.0
Oracle ≫ Hyperion Infrastructure Technology Version < 11.2.8.0
Oracle ≫ Identity Management Suite Version 12.2.1.3.0
Oracle ≫ Identity Management Suite Version 12.2.1.4.0
Oracle ≫ Identity Manager Connector Version 11.1.1.5.0
Oracle ≫ Jdeveloper Version 12.2.1.3.0
Oracle ≫ Middleware Common Libraries And Tools Version 12.2.1.4.0
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.29
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Oracle ≫ Weblogic Server Version 14.1.1.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 63.56% | 0.991 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
http://www.openwall.com/lists/oss-security/2022/01/18/3
https://lists.apache.org/thread/bsr3l5qz4g0myrjhy9h67bcxodpkwj4w
https://logging.apache.org/log4j/1.2/index.html
https://security.netapp.com/advisory/ntap-20220217-0006/
https://www.vicarius.io/vsociety/posts/cve-2022-23302-detect-log4j-1217-vulnerability
https://www.vicarius.io/vsociety/posts/cve-2022-23302-mitigate-log4j-1217-vulnerability