cbcvebase.
CVE-2022-23305
published 2022-01-18

CVE-2022-23305: By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from…

PriorityP274critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
66.54%
99.2th percentile
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
apachelog4j1.2 – 1.2.17
apache_software_foundationapache_log4j_1.x>= 1.2.1 < unspecifiedunspecified
apache_software_foundationapache_log4j_1.x>= unspecified < 2.0-alpha12.0-alpha1
debianapache-log4j1.2< apache-log4j1.2 1.2.17-11 (bookworm)apache-log4j1.2 1.2.17-11 (bookworm)
oracleadvanced_supply_chain_planning
oracleadvanced_supply_chain_planning
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_process_management_suite
oraclebusiness_process_management_suite
oraclecommunications_eagle_ftp_table_base_retrieval
oraclecommunications_instant_messaging_server
oraclecommunications_messaging_server
oraclecommunications_network_integrity
oraclecommunications_offline_mediation_controller< 12.0.0.4.412.0.0.4.4
oraclecommunications_offline_mediation_controller
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclee-business_suite_cloud_manager_and_cloud_backup_module< 2.2.1.1.12.2.1.1.1
oraclee-business_suite_cloud_manager_and_cloud_backup_module
oraclee-business_suite_information_discovery12.2.3 – 12.2.11
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oraclefinancial_services_revenue_management_and_billing_analytics

Detection & IOCsextracted from sources · hover to see the quote

  • SQL injection vector is the %m (message converter) in JDBCAppender's PatternLayout SQL configuration — monitor for SQL metacharacters in logged input fields or HTTP headers when JDBCAppender is in use
  • Vulnerability is only exploitable when Log4j 1.x is explicitly configured to use JDBCAppender — audit log4j configuration files for presence of JDBCAppender to determine exposure
  • Affected component path to monitor/block in deployed JARs: org/apache/log4j/jdbc/JDBCAppender.class
  • ·Vulnerability only affects Log4j 1.x (specifically 1.2.x) — Log4j 2.x re-introduced JDBCAppender with parameterized SQL queries and is not affected by this SQLi issue
  • ·Red Hat products using log4j-over-slf4j (e.g., Red Hat Satellite with Candlepin using logback) are not affected; JDBCAppender must actually be in use for exploitation
  • ·Red Hat Virtualization and OpenShift Container Platform (Hive/Presto/Hadoop) ship vulnerable log4j 1.x but JDBCAppender is not used, so impact is rated Low for those products
  • ·Apache Log4j 1.2 is end-of-life since August 2015; 32% of surveyed apps still use 1.2.x, making this a widespread latent risk

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.