SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-17571

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for…

CRITICAL 9.8EPSS 69.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 69.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
69.06% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
apache/log4j · debian/debian linux · canonical/ubuntu linux · opensuse/leap · netapp/oncommand system manager · netapp/oncommand workflow automation · oracle/application testing suite · oracle/communications network integrity · oracle/endeca information discovery studio · oracle/financial services lending and leasing · oracle/mysql enterprise monitor · oracle/primavera gateway · oracle/rapid planning · oracle/retail extract transform and load · oracle/retail service backbone · oracle/weblogic server · apache/bookkeeper
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.