cbcvebase.
CVE-2022-23307
published 2022-01-18

CVE-2022-23307: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
apachechainsaw< 2.1.02.1.0
apachelog4j>= 1.2 < 2.02.0
debianapache-log4j1.2< apache-log4j1.2 1.2.17-11 (bookworm)apache-log4j1.2 1.2.17-11 (bookworm)
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
oracleadvanced_supply_chain_planning
oracleadvanced_supply_chain_planning
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_process_management_suite
oraclebusiness_process_management_suite
oraclecommunications_eagle_ftp_table_base_retrieval
oraclecommunications_instant_messaging_server
oraclecommunications_messaging_server
oraclecommunications_network_integrity
oraclecommunications_offline_mediation_controller< 12.0.0.4.412.0.0.4.4
oraclecommunications_offline_mediation_controller
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oraclee-business_suite_cloud_manager_and_cloud_backup_module< 2.2.1.1.12.2.1.1.1
oraclee-business_suite_cloud_manager_and_cloud_backup_module
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oraclefinancial_services_revenue_management_and_billing_analytics
oraclefinancial_services_revenue_management_and_billing_analytics

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
osv9.8CRITICAL