SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-5645

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

CRITICAL 9.8EPSS 89.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 89.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
89.79% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
apache/log4j · netapp/oncommand api services · netapp/oncommand insight · netapp/oncommand workflow automation · netapp/service level manager · netapp/snapcenter · netapp/storage automation store · redhat/fuse · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · oracle/api gateway · oracle/application testing suite · oracle/autovue vuelink integration · oracle/banking platform · oracle/bi publisher · +40 more
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.