cbcvebase.
CVE-2022-23305
published 2022-01-18

CVE-2022-23305: By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
apachelog4j1.2 – 1.2.17
apache_software_foundationapache_log4j_1.x>= 1.2.1 < unspecifiedunspecified
apache_software_foundationapache_log4j_1.x>= unspecified < 2.0-alpha12.0-alpha1
debianapache-log4j1.2< apache-log4j1.2 1.2.17-11 (bookworm)apache-log4j1.2 1.2.17-11 (bookworm)
oracleadvanced_supply_chain_planning
oracleadvanced_supply_chain_planning
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_process_management_suite
oraclebusiness_process_management_suite
oraclecommunications_eagle_ftp_table_base_retrieval
oraclecommunications_instant_messaging_server
oraclecommunications_messaging_server
oraclecommunications_network_integrity
oraclecommunications_offline_mediation_controller< 12.0.0.4.412.0.0.4.4
oraclecommunications_offline_mediation_controller
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclee-business_suite_cloud_manager_and_cloud_backup_module< 2.2.1.1.12.2.1.1.1
oraclee-business_suite_cloud_manager_and_cloud_backup_module
oraclee-business_suite_information_discovery12.2.3 – 12.2.11
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oraclefinancial_services_revenue_management_and_billing_analytics

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL