9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Affected (174)
Products: Apache: Log4j · Netapp: Oncommand Api Services, Oncommand Insight, Oncommand Workflow Automation, Service Level Manager, Snapcenter, Storage Automation Store · Redhat: Enterprise Linux, Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Fuse · +1 more
Show all products
Apache: Log4j · Netapp: Oncommand Api Services, Oncommand Insight, Oncommand Workflow Automation, Service Level Manager, Snapcenter, Storage Automation Store · Redhat: Enterprise Linux, Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Fuse · Oracle: Api Gateway, Application Testing Suite, Autovue Vuelink Integration, Banking Platform, Bi Publisher, Communications Converged Application Server Service Controller, Communications Instant Messaging Server, Communications Interactive Session Recorder, Communications Messaging Server, Communications Network Integrity, Communications Online Mediation Controller, Communications Pricing Design Center, Communications Service Broker, Communications Webrtc Session Controller, Configuration Manager, Endeca Information Discovery Studio, Enterprise Data Quality, Enterprise Manager Base Platform, Enterprise Manager For Fusion Middleware, Enterprise Manager For Mysql Database, Enterprise Manager For Oracle Database, Enterprise Manager For Peoplesoft, Financial Services Analytical Applications Infrastructure, Financial Services Behavior Detection Platform, Financial Services Hedge Management And Ifrs Valuations, Financial Services Lending And Leasing, Financial Services Loan Loss Forecasting And Provisioning, Financial Services Profitability Management, Financial Services Regulatory Reporting With Agilereporter, Flexcube Investor Servicing, Fusion Middleware Mapviewer, Goldengate, Goldengate Application Adapters, Identity Analytics, Identity Management Suite, Identity Manager Connector, In Memory Performance Driven Planning, Instantis Enterprisetrack, Insurance Calculation Engine, Insurance Policy Administration, Insurance Rules Palette, Jd Edwards Enterpriseone Tools, Jdeveloper, Mysql Enterprise Monitor, Peoplesoft Enterprise Fin Install, Policy Automation, Policy Automation Connector For Siebel, Policy Automation For Mobile Devices, Primavera Gateway, Rapid Planning, Retail Advanced Inventory Planning, Retail Clearance Optimization Engine, Retail Extract Transform And Load, Retail Integration Bus, Retail Open Commerce Platform, Retail Predictive Application Server, Retail Service Backbone, Siebel Ui Framework, Soa Suite, Tape Library Acsls, Timesten In Memory Database, Utilities Advanced Spatial And Operational Analytics, Utilities Work And Asset Management, Weblogic Server
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 7.4 | |
| Version 7.4 | |
| Version 7.4 | |
| Version 7.0 | |
| Version 1.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.1.2.4.0 | |
| Version 13.3.0.1 | |
| Version 21.0.0 | |
| Version 2.6.0 | |
| Version 11.1.1.7.0 | |
| Version 6.1 | |
| Version 10.0.1.3.0 | |
| From 6.0 to 6.2 | |
| Before 8.0.2 | |
| From 7.3.2 to 7.3.6 | |
| Version 6.1 | |
| Version 11.1 | |
| Version 6.0 | |
| Before 7.2 | |
| Version 12.1.2.0.2 | |
| Version 3.2.0 | |
| Version 12.2.1.3.0 | |
| Version 12.1.0.5 | |
| Version 12.1.0.5 | |
| Up to 13.2.2.0.0 | |
| Version 12.1.0.8 | |
| Version 13.1.1.1 | |
| From 7.3.3.0.0 to 7.3.3.0.2 | |
| From 8.0.0.0.0 to 8.0.4.0.0 | |
| Version 8.0.4 | |
| From 14.1.0 to 14.8.0 | |
| Version 8.0.4 | |
| From 8.0.0.0.0 to 8.0.7.0.0 | |
| Version 8.0.9.2.0 | |
| Version 12.0.4 | |
| Version 12.2.1.2 | |
| Version 12.3.2.1.1 | |
| Version 12.3.2.1.1 | |
| Version 11.1.1.5.8 | |
| Version 11.1.2.3.0 | |
| Version 9.0 | |
| Version 12.1 | |
| From 17.1 to 17.3 | |
| Version 10.1.1 | |
| Version 10.0 | |
| Version 10.0 | |
| Version 4.0.1.0 | |
| Version 11.1.1.9.0 | |
| From 3.4.0.0 to 3.4.7.4297 | |
| Version 9.2 | |
| Version 10.4.7 | |
| Version 10.4.6 | |
| Version 10.4.7 | |
| From 16.2.0 to 16.2.11 | |
| Version 12.1 | |
| Version 14.0 | |
| Version 14.0.5 | |
| Version 13.0 | |
| Version 14.0.0 | |
| Version 5.3.0 | |
| Version 15.0.3 | |
| Version 14.1 | |
| Version 18.7 | |
| Version 12.1.3.0.0 | |
| Version 8.4 | |
| Version 11.2.2.8.49 | |
| Version 2.7.0.1 | |
| Version 1.9.1.2.12 | |
| Version 10.3.6.0.0 |
References (164)
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Patch
Source: security@apache.org
Patch
Source: security@apache.org
Patch
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Issue TrackingVendor Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.