← Back

CVE-2017-5645

Published: Apr 17, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

Affected (174)

Show all products
Apache: Log4j · Netapp: Oncommand Api Services, Oncommand Insight, Oncommand Workflow Automation, Service Level Manager, Snapcenter, Storage Automation Store · Redhat: Enterprise Linux, Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Fuse · Oracle: Api Gateway, Application Testing Suite, Autovue Vuelink Integration, Banking Platform, Bi Publisher, Communications Converged Application Server Service Controller, Communications Instant Messaging Server, Communications Interactive Session Recorder, Communications Messaging Server, Communications Network Integrity, Communications Online Mediation Controller, Communications Pricing Design Center, Communications Service Broker, Communications Webrtc Session Controller, Configuration Manager, Endeca Information Discovery Studio, Enterprise Data Quality, Enterprise Manager Base Platform, Enterprise Manager For Fusion Middleware, Enterprise Manager For Mysql Database, Enterprise Manager For Oracle Database, Enterprise Manager For Peoplesoft, Financial Services Analytical Applications Infrastructure, Financial Services Behavior Detection Platform, Financial Services Hedge Management And Ifrs Valuations, Financial Services Lending And Leasing, Financial Services Loan Loss Forecasting And Provisioning, Financial Services Profitability Management, Financial Services Regulatory Reporting With Agilereporter, Flexcube Investor Servicing, Fusion Middleware Mapviewer, Goldengate, Goldengate Application Adapters, Identity Analytics, Identity Management Suite, Identity Manager Connector, In Memory Performance Driven Planning, Instantis Enterprisetrack, Insurance Calculation Engine, Insurance Policy Administration, Insurance Rules Palette, Jd Edwards Enterpriseone Tools, Jdeveloper, Mysql Enterprise Monitor, Peoplesoft Enterprise Fin Install, Policy Automation, Policy Automation Connector For Siebel, Policy Automation For Mobile Devices, Primavera Gateway, Rapid Planning, Retail Advanced Inventory Planning, Retail Clearance Optimization Engine, Retail Extract Transform And Load, Retail Integration Bus, Retail Open Commerce Platform, Retail Predictive Application Server, Retail Service Backbone, Siebel Ui Framework, Soa Suite, Tape Library Acsls, Timesten In Memory Database, Utilities Advanced Spatial And Operational Analytics, Utilities Work And Asset Management, Weblogic Server
1 product
Log4j
6 products
Oncommand Api Services
Oncommand Insight
Oncommand Workflow Automation
Service Level Manager
Snapcenter
Storage Automation Store
8 products
Enterprise Linux
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Eus
Enterprise Linux Server Tus
Enterprise Linux Workstation
Fuse
64 products
Api Gateway
Application Testing Suite
Autovue Vuelink Integration
Banking Platform
Bi Publisher
Communications Messaging Server
Communications Network Integrity
Communications Service Broker
Configuration Manager
Enterprise Data Quality
Enterprise Manager Base Platform
Enterprise Manager For Peoplesoft
Flexcube Investor Servicing
Fusion Middleware Mapviewer
Goldengate
Goldengate Application Adapters
Identity Analytics
Identity Management Suite
Identity Manager Connector
Instantis Enterprisetrack
Insurance Calculation Engine
Insurance Policy Administration
Insurance Rules Palette
Jd Edwards Enterpriseone Tools
Jdeveloper
Mysql Enterprise Monitor
Peoplesoft Enterprise Fin Install
Policy Automation
Primavera Gateway
Rapid Planning
Retail Extract Transform And Load
Retail Integration Bus
Retail Open Commerce Platform
Retail Service Backbone
Siebel Ui Framework
Soa Suite
Tape Library Acsls
Timesten In Memory Database
Weblogic Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0 to 2.8.2
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
All versions
All versions
Configuration C
18 vulnerable
Configuration D
149 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.1.2.4.0
Version 13.3.0.1
Oracle
Version 21.0.0
Version 21.0.1
Oracle
Version 2.6.0
Version 2.6.1
Version 2.6.2
Oracle
Version 11.1.1.7.0
Version 11.1.1.9.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 6.1
Version 10.0.1.3.0
From 6.0 to 6.2
Before 8.0.2
From 7.3.2 to 7.3.6
Version 6.1
Oracle
Version 11.1
Version 12.0
Version 6.0
Before 7.2
Oracle
Version 12.1.2.0.2
Version 12.1.2.0.5
Version 3.2.0
Version 12.2.1.3.0
Oracle
Version 12.1.0.5
Version 13.2.0.0
Oracle
Version 12.1.0.5
Version 13.2.0.0
Up to 13.2.2.0.0
Oracle
Version 12.1.0.8
Version 13.2.2
Oracle
Version 13.1.1.1
Version 13.2.1.1
Oracle
From 7.3.3.0.0 to 7.3.3.0.2
From 8.0.0.0.0 to 8.0.7.0.0
Oracle
From 8.0.0.0.0 to 8.0.4.0.0
Version 6.1.1
Oracle
Version 8.0.4
Version 8.0.5
Oracle
From 14.1.0 to 14.8.0
Version 12.5.0
Oracle
Version 8.0.4
Version 8.0.5
Oracle
From 8.0.0.0.0 to 8.0.7.0.0
Version 6.1.1
Version 8.0.9.2.0
Oracle
Version 12.0.4
Version 12.1.0
Version 12.3.0
Version 12.4.0
Version 14.0.0
Oracle
Version 12.2.1.2
Version 12.2.1.3
Version 12.3.2.1.1
Version 12.3.2.1.1
Version 11.1.1.5.8
Oracle
Version 11.1.2.3.0
Version 12.2.1.3.0
Version 9.0
Oracle
Version 12.1
Version 12.2
From 17.1 to 17.3
Oracle
Version 10.1.1
Version 10.2.1
Oracle
Version 10.0
Version 10.1
Version 10.2
Version 11.0
Oracle
Version 10.0
Version 10.1
Version 10.2
Version 11.0
Version 11.1
Oracle
Version 4.0.1.0
Version 9.2
Oracle
Version 11.1.1.9.0
Version 12.1.3.0.0
Version 12.2.1.3.0
Oracle
From 3.4.0.0 to 3.4.7.4297
From 4.0.0.0 to 4.0.4.5235
From 8.0.0.0.0 to 8.0.0.8131
Version 9.2
Oracle
Version 10.4.7
Version 12.1.0
Version 12.1.1
Version 12.2.0
Version 12.2.10
Version 12.2.1
Version 12.2.2
Version 12.2.3
Version 12.2.4
Version 12.2.5
Version 12.2.6
Version 12.2.7
Version 12.2.8
Version 12.2.9
Version 10.4.6
Oracle
Version 10.4.7
Version 12.1.0
Version 12.1.1
Version 12.2.0
Version 12.2.10
Version 12.2.1
Version 12.2.2
Version 12.2.3
Version 12.2.4
Version 12.2.5
Version 12.2.6
Version 12.2.7
Version 12.2.8
Version 12.2.9
Oracle
From 16.2.0 to 16.2.11
From 17.12.0 to 17.12.7
Oracle
Version 12.1
Version 12.2
Oracle
Version 14.0
Version 15.0
Version 14.0.5
Oracle
Version 13.0
Version 13.1
Version 13.2
Version 19.0
Oracle
Version 14.0.0
Version 14.1.0
Version 15.0
Version 16.0
Oracle
Version 5.3.0
Version 6.0.0
Version 6.0.1
Version 15.0.3
Oracle
Version 14.1
Version 15.0
Version 16.0
Oracle
Version 18.7
Version 18.8
Version 18.9
Oracle
Version 12.1.3.0.0
Version 12.2.1.3.0
Version 12.2.2.0.0
Version 8.4
Version 11.2.2.8.49
Version 2.7.0.1
Version 1.9.1.2.12
Oracle
Version 10.3.6.0.0
Version 12.1.3.0.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 14.1.1.0.0

References (164)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Issue TrackingVendor Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.