peter bassill · operator
$ cve CVE-2017-5645 JSON

CVE-2017-5645

9.8
CRITICAL · CVSS 3.1 · EPSS 89.8% (pctl 100)

Patch early

EPSS 89.8% — above the 10% action threshold.

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS89.79% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2017-04-17
Last modified2026-06-17

Affected (40)

VendorProduct
apachelog4j
netapponcommand api services
netapponcommand insight
netapponcommand workflow automation
netappservice level manager
netappsnapcenter
netappstorage automation store
oracleapi gateway
oracleapplication testing suite
oracleautovue vuelink integration
oraclebanking platform
oraclebi publisher
oraclecommunications converged application server - service controller
oraclecommunications instant messaging server
oraclecommunications interactive session recorder
oraclecommunications messaging server
oraclecommunications network integrity
oraclecommunications online mediation controller
oraclecommunications pricing design center
oraclecommunications service broker
oraclecommunications webrtc session controller
oracleconfiguration manager
oracleendeca information discovery studio
oracleenterprise data quality
oracleenterprise manager base platform
oracleenterprise manager for fusion middleware
oracleenterprise manager for mysql database
oracleenterprise manager for oracle database
oracleenterprise manager for peoplesoft
oraclefinancial services analytical applications infrastructure
oraclefinancial services behavior detection platform
oraclefinancial services hedge management and ifrs valuations
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatfuse

References

→ the Explorer  ·  watch your stack  ·  NVD