← Back

CVE-2019-17571

nvd nist
Published: Dec 20, 2019Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

Affected (28)

Show all products
2 products
Log4j
Bookkeeper
1 product
Debian Linux
1 product
Ubuntu Linux
1 product
Leap
2 products
Oncommand System Manager
Oncommand Workflow Automation
10 products
Application Testing Suite
Communications Network Integrity
Mysql Enterprise Monitor
Primavera Gateway
Rapid Planning
Retail Extract Transform And Load
Retail Service Backbone
Weblogic Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.2.17
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Version 9.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 18.04
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
From 3.0 to 3.1.3
All versions
Configuration F
19 vulnerable
Vulnerable SoftwareAffected Versions
Version 13.3.0.1
From 7.3.2 to 7.3.6
Version 3.2.0
Oracle
From 14.1.0 to 14.8.0
Version 12.5.0
Up to 8.0.29
Oracle
From 16.2 to 16.2.11
From 17.12.0 to 17.12.7
Oracle
Version 12.1
Version 12.2
Version 19.0
Oracle
Version 14.1
Version 15.0
Version 16.0
Oracle
Version 10.3.6.0.0
Version 12.1.3.0.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 14.1.1.0.0
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.14.3

References (226)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.