CVE-2017-5645
9.8
CRITICAL · CVSS 3.1 · EPSS 89.8% (pctl 100)
Patch early
EPSS 89.8% — above the 10% action threshold.
Description
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 89.79% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-04-17 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| apache | log4j |
| netapp | oncommand api services |
| netapp | oncommand insight |
| netapp | oncommand workflow automation |
| netapp | service level manager |
| netapp | snapcenter |
| netapp | storage automation store |
| oracle | api gateway |
| oracle | application testing suite |
| oracle | autovue vuelink integration |
| oracle | banking platform |
| oracle | bi publisher |
| oracle | communications converged application server - service controller |
| oracle | communications instant messaging server |
| oracle | communications interactive session recorder |
| oracle | communications messaging server |
| oracle | communications network integrity |
| oracle | communications online mediation controller |
| oracle | communications pricing design center |
| oracle | communications service broker |
| oracle | communications webrtc session controller |
| oracle | configuration manager |
| oracle | endeca information discovery studio |
| oracle | enterprise data quality |
| oracle | enterprise manager base platform |
| oracle | enterprise manager for fusion middleware |
| oracle | enterprise manager for mysql database |
| oracle | enterprise manager for oracle database |
| oracle | enterprise manager for peoplesoft |
| oracle | financial services analytical applications infrastructure |
| oracle | financial services behavior detection platform |
| oracle | financial services hedge management and ifrs valuations |
| redhat | enterprise linux |
| redhat | enterprise linux desktop |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server eus |
| redhat | enterprise linux server tus |
| redhat | enterprise linux workstation |
| redhat | fuse |
References
- http://www.openwall.com/lists/oss-security/2019/12/19/2
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/97702
- http://www.securitytracker.com/id/1040200
- http://www.securitytracker.com/id/1041294
- https://access.redhat.com/errata/RHSA-2017:1417
- https://access.redhat.com/errata/RHSA-2017:1801
- https://access.redhat.com/errata/RHSA-2017:1802
- https://access.redhat.com/errata/RHSA-2017:2423
- https://access.redhat.com/errata/RHSA-2017:2633
- https://access.redhat.com/errata/RHSA-2017:2635
- https://access.redhat.com/errata/RHSA-2017:2636
- https://access.redhat.com/errata/RHSA-2017:2637
- https://access.redhat.com/errata/RHSA-2017:2638
- https://access.redhat.com/errata/RHSA-2017:2808
- https://access.redhat.com/errata/RHSA-2017:2809
- https://access.redhat.com/errata/RHSA-2017:2810
→ the Explorer · watch your stack · NVD