CVE-2022-23307
published 2022-01-18CVE-2022-23307: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x…
PriorityP265high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
52.46%
98.8th percentile
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | chainsaw | < 2.1.0 | 2.1.0 |
| apache | log4j | >= 1.2 < 2.0 | 2.0 |
| debian | apache-log4j1.2 | < apache-log4j1.2 1.2.17-11 (bookworm) | apache-log4j1.2 1.2.17-11 (bookworm) |
| linux | linux_kernel | >= 0 < 5.15.0-116.126 | 5.15.0-116.126 |
| oracle | advanced_supply_chain_planning | — | — |
| oracle | advanced_supply_chain_planning | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | communications_eagle_ftp_table_base_retrieval | — | — |
| oracle | communications_instant_messaging_server | — | — |
| oracle | communications_messaging_server | — | — |
| oracle | communications_network_integrity | — | — |
| oracle | communications_offline_mediation_controller | < 12.0.0.4.4 | 12.0.0.4.4 |
| oracle | communications_offline_mediation_controller | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | e-business_suite_cloud_manager_and_cloud_backup_module | < 2.2.1.1.1 | 2.2.1.1.1 |
| oracle | e-business_suite_cloud_manager_and_cloud_backup_module | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | financial_services_revenue_management_and_billing_analytics | — | — |
| oracle | financial_services_revenue_management_and_billing_analytics | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-23307 is the same vulnerability as CVE-2020-9493 — the Chainsaw component of Apache Log4j 1.2.x performs unsafe deserialization of log events, enabling remote code execution. Detection should focus on Chainsaw being invoked alongside log4j 1.2.x. ↗
- →The attack vector requires an attacker to send a malicious request containing serialized data to a server running the Chainsaw component; monitor for unexpected deserialization activity in processes associated with log4j 1.2.x Chainsaw. ↗
- →Log4j 1.2.x (end-of-life since August 2015) is the affected version range; inventory applications using Log4j versions 1.2.x as a detection/triage signal. ↗
- ·The vulnerability only manifests when the Chainsaw component is actively run; products shipping log4j 1.2.x but not using Chainsaw are not exploitable via this vector. ↗
- ·Red Hat Satellite bundles log4j-over-slf4j with Candlepin but is not affected because it uses the logback framework for logging, not log4j 1.2.x Chainsaw. ↗
- ·In OpenShift Container Platform, the Hive/Presto/Hadoop Metering stack ships the vulnerable log4j package but the Chainsaw component is not used by default, reducing impact to Low. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
apache-log4j1.2 vulnerabilities
osv·2025-06-23·CVSS 8.8
CVE-2022-23302 [HIGH] apache-log4j1.2 vulnerabilities
apache-log4j1.2 vulnerabilities
It was discovered that several deserialization issues existed within Apache
Log4j. An attacker could possibly use these issues to enable the execution
of arbitrary code. (CVE-2022-23302, CVE-2022-23305, CVE-2022-23307)
OSV
linux-xilinx-zynqmp vulnerabilities
osv·2024-09-18·CVSS 5.5
CVE-2022-38096 linux-xilinx-zynqmp vulnerabilities
linux-xilinx-zynqmp vulnerabilities
Ziming Zhang discovered that the DRM driver for VMware Virtual GPU did not
properly handle certain error conditions, leading to a NULL pointer
dereference. A local attacker could possibly trigger this vulnerability to
cause a denial of service. (CVE-2022-38096)
Gui-Dong Han discovered that the software RAID driver in the Linux kernel
contained a race condition, leading to an integer overflow vulnerability. A
privileged attacker could possibly use this to cause a denial of service
(system crash). (CVE-2024-23307)
Chenyuan Yang discovered that the CEC driver driver in the Linux kernel
contained a use-after-free vulnerability. A local attacker could use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2024-23848)
OSV
linux-gcp-5.15 vulnerabilities
osv·2024-07-30·CVSS 5.5
CVE-2022-38096 linux-gcp-5.15 vulnerabilities
linux-gcp-5.15 vulnerabilities
Ziming Zhang discovered that the DRM driver for VMware Virtual GPU did not
properly handle certain error conditions, leading to a NULL pointer
dereference. A local attacker could possibly trigger this vulnerability to
cause a denial of service. (CVE-2022-38096)
Gui-Dong Han discovered that the software RAID driver in the Linux kernel
contained a race condition, leading to an integer overflow vulnerability. A
privileged attacker could possibly use this to cause a denial of service
(system crash). (CVE-2024-23307)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel when modifying certain settings values through debugfs.
A privileged local attacker could use this to cause a denial of service.
(CVE-2024-24857, CVE-202
OSV
linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15 vulnerabilities
osv·2024-07-26·CVSS 5.5
CVE-2022-38096 linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15 vulnerabilities
linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15 vulnerabilities
Ziming Zhang discovered that the DRM driver for VMware Virtual GPU did not
properly handle certain error conditions, leading to a NULL pointer
dereference. A local attacker could possibly trigger this vulnerability to
cause a denial of service. (CVE-2022-38096)
Gui-Dong Han discovered that the software RAID driver in the Linux kernel
contained a race condition, leading to an integer overflow vulnerability. A
privileged attacker could possibly use this to cause a denial of service
(system crash). (CVE-2024-23307)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel when modifying certain settings values through debugfs.
A privileged local attacker could use this
OSV
linux-aws-5.15 vulnerabilities
osv·2024-07-23·CVSS 5.5
CVE-2022-38096 linux-aws-5.15 vulnerabilities
linux-aws-5.15 vulnerabilities
Ziming Zhang discovered that the DRM driver for VMware Virtual GPU did not
properly handle certain error conditions, leading to a NULL pointer
dereference. A local attacker could possibly trigger this vulnerability to
cause a denial of service. (CVE-2022-38096)
Gui-Dong Han discovered that the software RAID driver in the Linux kernel
contained a race condition, leading to an integer overflow vulnerability. A
privileged attacker could possibly use this to cause a denial of service
(system crash). (CVE-2024-23307)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel when modifying certain settings values through debugfs.
A privileged local attacker could use this to cause a denial of service.
(CVE-2024-24857, CVE-202
OSV
linux-aws, linux-hwe-5.15 vulnerabilities
osv·2024-07-19·CVSS 5.5
CVE-2022-38096 linux-aws, linux-hwe-5.15 vulnerabilities
linux-aws, linux-hwe-5.15 vulnerabilities
Ziming Zhang discovered that the DRM driver for VMware Virtual GPU did not
properly handle certain error conditions, leading to a NULL pointer
dereference. A local attacker could possibly trigger this vulnerability to
cause a denial of service. (CVE-2022-38096)
Gui-Dong Han discovered that the software RAID driver in the Linux kernel
contained a race condition, leading to an integer overflow vulnerability. A
privileged attacker could possibly use this to cause a denial of service
(system crash). (CVE-2024-23307)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel when modifying certain settings values through debugfs.
A privileged local attacker could use this to cause a denial of service.
(CVE-2024-248
OSV
linux-ibm-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle-5.15 vulnerabilities
osv·2024-07-17·CVSS 5.5
CVE-2022-38096 linux-ibm-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle-5.15 vulnerabilities
linux-ibm-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle-5.15 vulnerabilities
Ziming Zhang discovered that the DRM driver for VMware Virtual GPU did not
properly handle certain error conditions, leading to a NULL pointer
dereference. A local attacker could possibly trigger this vulnerability to
cause a denial of service. (CVE-2022-38096)
Gui-Dong Han discovered that the software RAID driver in the Linux kernel
contained a race condition, leading to an integer overflow vulnerability. A
privileged attacker could possibly use this to cause a denial of service
(system crash). (CVE-2024-23307)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel when modifying certain settings values through debugfs.
A privileged local attacker could
OSV
linux, linux-gcp, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-ibm, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-nvidia, linux-oracle vulnerabilities
osv·2024-07-15·CVSS 5.5
CVE-2022-38096 linux, linux-gcp, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-ibm, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-nvidia, linux-oracle vulnerabilities
linux, linux-gcp, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-ibm, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-nvidia, linux-oracle vulnerabilities
Ziming Zhang discovered that the DRM driver for VMware Virtual GPU did not
properly handle certain error conditions, leading to a NULL pointer
dereference. A local attacker could possibly trigger this vulnerability to
cause a denial of service. (CVE-2022-38096)
Gui-Dong Han discovered that the software RAID driver in the Linux kernel
contained a race condition, leading to an integer overflow vulnerability. A
privileged attacker could possibly use this to cause a denial of service
(system crash). (CVE-2024-23307)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel when modifying cer
OSV
apache-log4j1.2 vulnerabilities
osv·2023-04-05·CVSS 9.8
CVE-2019-17571 [CRITICAL] apache-log4j1.2 vulnerabilities
apache-log4j1.2 vulnerabilities
It was discovered that the SocketServer component of Apache Log4j 1.2
incorrectly handled deserialization. An attacker could possibly use this issue
to execute arbitrary code. This issue only affected Ubuntu 16.04 ESM.
(CVE-2019-17571)
It was discovered that the JMSSink component of Apache Log4j 1.2 incorrectly
handled deserialization. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2022-23302)
It was discovered that Apache Log4j 1.2 incorrectly handled certain SQL
statements. A remote attacker could possibly use this issue to perform an SQL
injection attack and alter the database. This issue was only fixed in Ubuntu
18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-23305)
It was discovered that the Chainsaw component of Apache Log4j 1.
OSV
Deserialization of Untrusted Data in Apache Log4j
osv·2022-01-19·CVSS 9.8
CVE-2022-23307 [CRITICAL] Deserialization of Untrusted Data in Apache Log4j
Deserialization of Untrusted Data in Apache Log4j
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Users are advised to migrate from `log4j:log4j` to `org.apache.logging.log4j:log4j` for an updated version of the library.
GHSA
Deserialization of Untrusted Data in Apache Log4j
ghsa·2022-01-19·CVSS 9.8
CVE-2022-23307 [CRITICAL] CWE-502 Deserialization of Untrusted Data in Apache Log4j
Deserialization of Untrusted Data in Apache Log4j
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Users are advised to migrate from `log4j:log4j` to `org.apache.logging.log4j:log4j` for an updated version of the library.
OSV
CVE-2022-23307: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw
osv·2022-01-18·CVSS 9.8
CVE-2022-23307 [CRITICAL] CVE-2022-23307: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Ubuntu
Apache Log4j vulnerabilities
vendor_ubuntu·2025-06-23·CVSS 8.8
CVE-2022-23302 [HIGH] Apache Log4j vulnerabilities
Title: Apache Log4j vulnerabilities
Summary: Apache Log4j could be made to run programs as your login if it opened a
specially crafted file.
It was discovered that several deserialization issues existed within Apache
Log4j. An attacker could possibly use these issues to enable the execution
of arbitrary code. (CVE-2022-23302, CVE-2022-23305, CVE-2022-23307)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Apache Log4j vulnerabilities
vendor_ubuntu·2023-04-05·CVSS 9.8
CVE-2019-17571 [CRITICAL] Apache Log4j vulnerabilities
Title: Apache Log4j vulnerabilities
Summary: Several security issues were fixed in Apache Log4j.
It was discovered that the SocketServer component of Apache Log4j 1.2
incorrectly handled deserialization. An attacker could possibly use this issue
to execute arbitrary code. This issue only affected Ubuntu 16.04 ESM.
(CVE-2019-17571)
It was discovered that the JMSSink component of Apache Log4j 1.2 incorrectly
handled deserialization. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2022-23302)
It was discovered that Apache Log4j 1.2 incorrectly handled certain SQL
statements. A remote attacker could possibly use this issue to perform an SQL
injection attack and alter the database. This issue was only fixed in Ubuntu
18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-23305)
Red Hat
log4j: Unsafe deserialization flaw in Chainsaw log viewer
vendor_redhat·2022-01-18·CVSS 9.8
CVE-2022-23307 [CRITICAL] CWE-502 log4j: Unsafe deserialization flaw in Chainsaw log viewer
log4j: Unsafe deserialization flaw in Chainsaw log viewer
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
A flaw was found in the log4j 1.x chainsaw component, where the contents of certain log entries are deserialized and possibly permit code execution. This flaw allows an attacker to send a malicious request with serialized data to the server to be deserialized when the chainsaw component is run.
Statement: Chainsaw is a standalone graphical user interface for viewing log entries in log4j. This flaw may be bypassed by using other available means to access log entries.
Red Hat Satellite bundles log4j-over-slf4j with Candlepin, however, product is not
Debian
CVE-2022-23307: apache-log4j1.2 - CVE-2020-9493 identified a deserialization issue that was present in Apache Chai...
vendor_debian·2022·CVSS 9.8
CVE-2022-23307 [CRITICAL] CVE-2022-23307: apache-log4j1.2 - CVE-2020-9493 identified a deserialization issue that was present in Apache Chai...
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Scope: local
bookworm: resolved (fixed in 1.2.17-11)
bullseye: resolved (fixed in 1.2.17-10+deb11u1)
forky: resolved (fixed in 1.2.17-11)
sid: resolved (fixed in 1.2.17-11)
trixie: resolved (fixed in 1.2.17-11)
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Over 30% of Log4J apps use a vulnerable version of the library
blogs_bleepingcomputer·2023-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Over 30% of Log4J apps use a vulnerable version of the library
## Over 30% of Log4J apps use a vulnerable version of the library
## Bill Toulas
Roughly 38% of applications using the Apache Log4j library are using a version vulnerable to security issues, including Log4Shell, a critical vulnerability identified as CVE-2021-44228 that carries the maximum severity rating, despite patches being available for more than two years.
Log4Shell is an unauthenticated remote code execution (RCE) flaw that allows taking complete control over systems with Log4j 2.0-beta9 and up to 2.15.0.
The flaw was discovered as an actively exploited zero-day on December 10, 2021, and its widespread impact, ease of exploitation, and massive security implications acted as an open invitation to threat actors.
The circumstance prompted an extensive campaign to notify affected p
Tenable
Oracle July 2022 Critical Patch Update Addresses 188 CVEs
blogs_tenable·2022-07-20
Oracle July 2022 Critical Patch Update Addresses 188 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2022-23307 log4j: Unsafe deserialization flaw in Chainsaw log viewer
bugzilla·2022-01-18·CVSS 9.8
CVE-2022-23307 [CRITICAL] CVE-2022-23307 log4j: Unsafe deserialization flaw in Chainsaw log viewer
CVE-2022-23307 log4j: Unsafe deserialization flaw in Chainsaw log viewer
A deserialization flaw was found in Apache log4j 1.2.x. While reading serialized log events, they are improperly deserialized.
Note this is the same as CVE-2020-9493 which identified a deserialization issue in Apache Chainsaw. Prior to Chainsaw V2.0, Chainsaw was a component of Apache Log4j 1.2.x.
References:
https://www.openwall.com/lists/oss-security/2022/01/18/5
Discussion:
Marking /services "notaffected" per previous analysis/remediation.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
Via RHSA-2022:0294 https://access.redhat.com/errata/RHSA-2022:0294
---
This issue has been addressed in the following products:
Red Hat Enterpr
arXiv
Attack Techniques and Threat Identification for Vulnerabilities
arxiv_fulltext·2022-06-22
Attack Techniques and Threat Identification for Vulnerabilities
Attack Techniques and Threat Identification for Vulnerabilities
Constantin Adam
Muhammed Fatih Bulut
Daby Sow
cmadam, mfbulut, [email protected]
IBM T.J. Watson Research Center
Yorktown Heights
NY
USA
Steven Ocepek
Chris Bedell
steve.ocepek, [email protected]
IBM Security X-Force Red
USA
Lilian Ngweta
[email protected]
Rensselaer Polytechnic Institute
Troy
NY
USA
Adam and Bulut, et al.
## Abstract
Modern organizations struggle with what is often considered an insurmountable number of vulnerabilities that are discovered and reported by their network and application vulnerability scanners. Therefore, prioritization and focus become critical, to spend their limited time on the highest risk vulnerabilities. In doing this, it is important for these organizations not only to
https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhhhttps://logging.apache.org/log4j/1.2/index.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhhhttps://logging.apache.org/log4j/1.2/index.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2022-01-18
Published