CVE-2017-5645
Last modified
CVE-2017-5645 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.. EPSS estimates a 89.04% chance of exploitation in the next 30 days.
Description
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Log4j | >= 2.0, < 2.8.2 |
| Netapp | Oncommand Api Services | All versions |
| Netapp | Oncommand Insight | All versions |
| Netapp | Oncommand Workflow Automation | All versions |
| Netapp | Service Level Manager | All versions |
| Netapp | Snapcenter | All versions |
| Netapp | Storage Automation Store | All versions |
| Redhat | Fuse | 1.0 |
| Redhat | Enterprise Linux | 6.0 |
| Redhat | Enterprise Linux | 6.7 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux | 7.3 |
| Redhat | Enterprise Linux | 7.4 |
| Redhat | Enterprise Linux | 7.5 |
| Redhat | Enterprise Linux | 7.6 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.4 |
| Redhat | Enterprise Linux Server Aus | 7.6 |
| Redhat | Enterprise Linux Server Eus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.5 |
| Redhat | Enterprise Linux Server Eus | 7.6 |
| Redhat | Enterprise Linux Server Tus | 7.4 |
| Redhat | Enterprise Linux Server Tus | 7.6 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Oracle | Api Gateway | 11.1.2.4.0 |
| Oracle | Application Testing Suite | 13.3.0.1 |
| Oracle | Autovue Vuelink Integration | 21.0.0 |
| Oracle | Autovue Vuelink Integration | 21.0.1 |
| Oracle | Banking Platform | 2.6.0 |
| Oracle | Banking Platform | 2.6.1 |
| Oracle | Banking Platform | 2.6.2 |
| Oracle | Bi Publisher | 11.1.1.7.0 |
| Oracle | Bi Publisher | 11.1.1.9.0 |
| Oracle | Bi Publisher | 12.2.1.3.0 |
| Oracle | Bi Publisher | 12.2.1.4.0 |
| Oracle | Communications Converged Application Server - Service Controller | 6.1 |
| Oracle | Communications Instant Messaging Server | 10.0.1.3.0 |
| Oracle | Communications Interactive Session Recorder | >= 6.0, <= 6.2 |
| Oracle | Communications Messaging Server | < 8.0.2 |
| Oracle | Communications Network Integrity | >= 7.3.2, <= 7.3.6 |
| Oracle | Communications Online Mediation Controller | 6.1 |
| Oracle | Communications Pricing Design Center | 11.1 |
| Oracle | Communications Pricing Design Center | 12.0 |
| Oracle | Communications Service Broker | 6.0 |
| Oracle | Communications Webrtc Session Controller | < 7.2 |
| Oracle | Configuration Manager | 12.1.2.0.2 |
| Oracle | Configuration Manager | 12.1.2.0.5 |
| Oracle | Endeca Information Discovery Studio | 3.2.0 |
| Oracle | Enterprise Data Quality | 12.2.1.3.0 |
Showing 50 of 174 affected configurations. See NVD for the full list.
References
- http://www.openwall.com/lists/oss-security/2019/12/19/2Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/97702Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040200Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041294Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1417Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1801Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1802Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2423Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2633Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2635Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2636Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2637Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2638Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2808Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2809Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2810Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2811Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2888Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2889Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3244Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3399Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3400Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1545Third Party Advisory
- https://issues.apache.org/jira/browse/LOG4J2-1863Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20180726-0002/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20181107-0002/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlPatch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/12/19/2Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/97702Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040200Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041294Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1417Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1801Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1802Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2423Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2633Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2635Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2636Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2637Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2638Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2808Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2809Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2810Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2811Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2888Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2889Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3244Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3399Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3400Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1545Third Party Advisory
- https://issues.apache.org/jira/browse/LOG4J2-1863Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20180726-0002/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20181107-0002/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5645?
How severe is CVE-2017-5645?
How do I fix CVE-2017-5645?
Are you affected by CVE-2017-5645?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
