cbcvebase.
CVE-2017-5645
published 2017-04-17

CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

Affected

171 ranges· showing 25
VendorProductVersion rangeFixed in
apachelog4j>= 2.0 < 2.8.22.8.2
apachelogging
apache_software_foundationapache_log4j
debianapache-log4j2< apache-log4j2 2.7-2 (bookworm)apache-log4j2 2.7-2 (bookworm)
oracleapi_gateway
oracleapplication_testing_suite
oracleautovue_vuelink_integration
oracleautovue_vuelink_integration
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebi_publisher
oraclebi_publisher
oraclebi_publisher
oraclebi_publisher
oraclecommunications_converged_application_server_service_controller
oraclecommunications_instant_messaging_server
oraclecommunications_interactive_session_recorder6.0 – 6.2
oraclecommunications_messaging_server< 8.0.28.0.2
oraclecommunications_network_integrity7.3.2 – 7.3.6
oraclecommunications_online_mediation_controller
oraclecommunications_pricing_design_center
oraclecommunications_pricing_design_center
oraclecommunications_service_broker
oraclecommunications_webrtc_session_controller< 7.27.2

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL