CVE-2017-5645
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 89.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 89.79% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- apache/log4j · netapp/oncommand api services · netapp/oncommand insight · netapp/oncommand workflow automation · netapp/service level manager · netapp/snapcenter · netapp/storage automation store · redhat/fuse · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · oracle/api gateway · oracle/application testing suite · oracle/autovue vuelink integration · oracle/banking platform · oracle/bi publisher · +40 more
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2019/12/19/2Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/97702Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040200Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041294Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1417Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1801Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1802Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2423Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2633Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2635Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2636Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2637Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2638Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2808Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2809Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2810Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2811Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2888Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2889Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3244Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3399Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3400Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1545Third Party Advisory
- https://issues.apache.org/jira/browse/LOG4J2-1863Issue Tracking, Vendor Advisory
- https://lists.apache.org/thread.html/0dcca05274d20ef2d72584edcf8c917bbb13dbbd7eb35cae909d02e9%40%3Cdev.logging.apache.org%3E
- https://lists.apache.org/thread.html/277b4b5c2b0e06a825ccec565fa65bd671f35a4d58e3e2ec5d0618e1%40%3Cdev.tika.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.