CVE-2022-23305

CWE-89SQL Injection18 documents8 sources
Severity
9.8CRITICAL
EPSS
8.0%
top 7.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18
Latest updateJun 23

Description

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender,

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages31 packages

CVEListV5apache_software_foundation/apache_log4j_1.x1.2.1unspecified+1
Debianapache-log4j1.2< 1.2.17-10+deb11u1+3
Ubuntuapache-log4j1.2< 1.2.17-4ubuntu3+esm2
NVDapache/log4j1.21.2.17
Mavenlog4j:log4j1.2.17

Patches

🔴Vulnerability Details

6
OSV
apache-log4j1.2 vulnerabilities2025-06-23
OSV
apache-log4j1.2 vulnerabilities2023-04-05
GHSA
SQL Injection in Log4j 1.2.x2022-01-21
OSV
SQL Injection in Log4j 1.2.x2022-01-21
CVEList
SQL injection in JDBC Appender in Apache Log4j V12022-01-18

📋Vendor Advisories

11
Ubuntu
Apache Log4j vulnerabilities2025-06-23
Oracle
Oracle Oracle Analytics Risk Matrix: BI Application Archive (Apache Log4j) — CVE-2022-233052024-10-15
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache Log4j) — CVE-2022-233052023-07-15
Oracle
Oracle Oracle Utilities Applications Risk Matrix: General (Apache Log4j) — CVE-2022-233052023-04-15
Ubuntu
Apache Log4j vulnerabilities2023-04-05
CVE-2022-23305 (CRITICAL CVSS 9.8) | By design | cvebase.io