cbcvebase.
CVE-2019-17571
published 2019-12-20

CVE-2019-17571: Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
apachebookkeeper< 4.14.34.14.3
apachelog4j<= 1.2.17
apache_software_foundationlog4j
canonicalubuntu_linux
debianapache-log4j1.2< apache-log4j1.2 1.2.17-9 (bookworm)apache-log4j1.2 1.2.17-9 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
netapponcommand_system_manager3.0 – 3.1.3
opensuseleap
oracleapplication_testing_suite
oraclecommunications_network_integrity7.3.2 – 7.3.6
oracleendeca_information_discovery_studio
oraclefinancial_services_lending_and_leasing
oraclefinancial_services_lending_and_leasing14.1.0 – 14.8.0
oraclemysql_enterprise_monitor<= 8.0.29
oracleprimavera_gateway16.2 – 16.2.11
oracleprimavera_gateway17.12.0 – 17.12.7
oraclerapid_planning
oraclerapid_planning
oracleretail_extract_transform_and_load
oracleretail_service_backbone
oracleretail_service_backbone
oracleretail_service_backbone
oracleweblogic_server

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL