CVE-2017-5645

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
apachelog4j
2.0 ≤
𝑥
< 2.8.2
netapponcommand_api_services
-
netapponcommand_insight
-
netapponcommand_workflow_automation
-
netappservice_level_manager
-
netappsnapcenter
-
netappstorage_automation_store
-
redhatfuse
1.0
redhatenterprise_linux
6.0
redhatenterprise_linux
6.7
redhatenterprise_linux
7.0
redhatenterprise_linux
7.3
redhatenterprise_linux
7.4
redhatenterprise_linux
7.5
redhatenterprise_linux
7.6
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_eus
7.4
redhatenterprise_linux_server_eus
7.5
redhatenterprise_linux_server_eus
7.6
redhatenterprise_linux_server_tus
7.4
redhatenterprise_linux_server_tus
7.6
redhatenterprise_linux_workstation
7.0
oracleapi_gateway
11.1.2.4.0
oracleapplication_testing_suite
13.3.0.1
oracleautovue_vuelink_integration
21.0.0
oracleautovue_vuelink_integration
21.0.1
oraclebanking_platform
2.6.0
oraclebanking_platform
2.6.1
oraclebanking_platform
2.6.2
oraclebi_publisher
11.1.1.7.0
oraclebi_publisher
11.1.1.9.0
oraclebi_publisher
12.2.1.3.0
oraclebi_publisher
12.2.1.4.0
oraclecommunications_converged_application_server_-_service_controller
6.1
oraclecommunications_instant_messaging_server
10.0.1.3.0
oraclecommunications_interactive_session_recorder
6.0 ≤
𝑥
≤ 6.2
oraclecommunications_messaging_server
𝑥
< 8.0.2
oraclecommunications_network_integrity
7.3.2 ≤
𝑥
≤ 7.3.6
oraclecommunications_online_mediation_controller
6.1
oraclecommunications_pricing_design_center
11.1
oraclecommunications_pricing_design_center
12.0
oraclecommunications_service_broker
6.0
oraclecommunications_webrtc_session_controller
𝑥
< 7.2
oracleconfiguration_manager
12.1.2.0.2
oracleconfiguration_manager
12.1.2.0.5
oracleendeca_information_discovery_studio
3.2.0
oracleenterprise_data_quality
12.2.1.3.0
oracleenterprise_manager_base_platform
12.1.0.5
oracleenterprise_manager_base_platform
13.2.0.0
oracleenterprise_manager_for_fusion_middleware
12.1.0.5
oracleenterprise_manager_for_fusion_middleware
13.2.0.0
oracleenterprise_manager_for_mysql_database
𝑥
≤ 13.2.2.0.0
oracleenterprise_manager_for_oracle_database
12.1.0.8
oracleenterprise_manager_for_oracle_database
13.2.2
oracleenterprise_manager_for_peoplesoft
13.1.1.1
oracleenterprise_manager_for_peoplesoft
13.2.1.1
oraclefinancial_services_analytical_applications_infrastructure
7.3.3.0.0 ≤
𝑥
≤ 7.3.3.0.2
oraclefinancial_services_analytical_applications_infrastructure
8.0.0.0.0 ≤
𝑥
≤ 8.0.7.0.0
oraclefinancial_services_behavior_detection_platform
8.0.0.0.0 ≤
𝑥
≤ 8.0.4.0.0
oraclefinancial_services_behavior_detection_platform
6.1.1
oraclefinancial_services_hedge_management_and_ifrs_valuations
8.0.4
oraclefinancial_services_hedge_management_and_ifrs_valuations
8.0.5
oraclefinancial_services_lending_and_leasing
14.1.0 ≤
𝑥
≤ 14.8.0
oraclefinancial_services_lending_and_leasing
12.5.0
oraclefinancial_services_loan_loss_forecasting_and_provisioning
8.0.4
oraclefinancial_services_loan_loss_forecasting_and_provisioning
8.0.5
oraclefinancial_services_profitability_management
8.0.0.0.0 ≤
𝑥
≤ 8.0.7.0.0
oraclefinancial_services_profitability_management
6.1.1
oraclefinancial_services_regulatory_reporting_with_agilereporter
8.0.9.2.0
oracleflexcube_investor_servicing
12.0.4
oracleflexcube_investor_servicing
12.1.0
oracleflexcube_investor_servicing
12.3.0
oracleflexcube_investor_servicing
12.4.0
oracleflexcube_investor_servicing
14.0.0
oraclefusion_middleware_mapviewer
12.2.1.2
oraclefusion_middleware_mapviewer
12.2.1.3
oraclegoldengate
12.3.2.1.1
oraclegoldengate_application_adapters
12.3.2.1.1
oracleidentity_analytics
11.1.1.5.8
oracleidentity_management_suite
11.1.2.3.0
oracleidentity_management_suite
12.2.1.3.0
oracleidentity_manager_connector
9.0
oraclein-memory_performance-driven_planning
12.1
oraclein-memory_performance-driven_planning
12.2
oracleinstantis_enterprisetrack
17.1 ≤
𝑥
≤ 17.3
oracleinsurance_calculation_engine
10.1.1
oracleinsurance_calculation_engine
10.2.1
oracleinsurance_policy_administration
10.0
oracleinsurance_policy_administration
10.1
oracleinsurance_policy_administration
10.2
oracleinsurance_policy_administration
11.0
oracleinsurance_rules_palette
10.0
oracleinsurance_rules_palette
10.1
oracleinsurance_rules_palette
10.2
oracleinsurance_rules_palette
11.0
oracleinsurance_rules_palette
11.1
oraclejd_edwards_enterpriseone_tools
4.0.1.0
oraclejd_edwards_enterpriseone_tools
9.2
oraclejdeveloper
11.1.1.9.0
oraclejdeveloper
12.1.3.0.0
oraclejdeveloper
12.2.1.3.0
oraclemysql_enterprise_monitor
3.4.0.0 ≤
𝑥
≤ 3.4.7.4297
oraclemysql_enterprise_monitor
4.0.0.0 ≤
𝑥
≤ 4.0.4.5235
oraclemysql_enterprise_monitor
8.0.0.0.0 ≤
𝑥
≤ 8.0.0.8131
oraclepeoplesoft_enterprise_fin_install
9.2
oraclepolicy_automation
10.4.7
oraclepolicy_automation
12.1.0
oraclepolicy_automation
12.1.1
oraclepolicy_automation
12.2.0
oraclepolicy_automation
12.2.1
oraclepolicy_automation
12.2.2
oraclepolicy_automation
12.2.3
oraclepolicy_automation
12.2.4
oraclepolicy_automation
12.2.5
oraclepolicy_automation
12.2.6
oraclepolicy_automation
12.2.7
oraclepolicy_automation
12.2.8
oraclepolicy_automation
12.2.9
oraclepolicy_automation
12.2.10
oraclepolicy_automation_connector_for_siebel
10.4.6
oraclepolicy_automation_for_mobile_devices
10.4.7
oraclepolicy_automation_for_mobile_devices
12.1.0
oraclepolicy_automation_for_mobile_devices
12.1.1
oraclepolicy_automation_for_mobile_devices
12.2.0
oraclepolicy_automation_for_mobile_devices
12.2.1
oraclepolicy_automation_for_mobile_devices
12.2.2
oraclepolicy_automation_for_mobile_devices
12.2.3
oraclepolicy_automation_for_mobile_devices
12.2.4
oraclepolicy_automation_for_mobile_devices
12.2.5
oraclepolicy_automation_for_mobile_devices
12.2.6
oraclepolicy_automation_for_mobile_devices
12.2.7
oraclepolicy_automation_for_mobile_devices
12.2.8
oraclepolicy_automation_for_mobile_devices
12.2.9
oraclepolicy_automation_for_mobile_devices
12.2.10
oracleprimavera_gateway
16.2.0 ≤
𝑥
≤ 16.2.11
oracleprimavera_gateway
17.12.0 ≤
𝑥
≤ 17.12.7
oraclerapid_planning
12.1
oraclerapid_planning
12.2
oracleretail_advanced_inventory_planning
14.0
oracleretail_advanced_inventory_planning
15.0
oracleretail_clearance_optimization_engine
14.0.5
oracleretail_extract_transform_and_load
13.0
oracleretail_extract_transform_and_load
13.1
oracleretail_extract_transform_and_load
13.2
oracleretail_extract_transform_and_load
19.0
oracleretail_integration_bus
14.0.0
oracleretail_integration_bus
14.1.0
oracleretail_integration_bus
15.0
oracleretail_integration_bus
16.0
oracleretail_open_commerce_platform
5.3.0
oracleretail_open_commerce_platform
6.0.0
oracleretail_open_commerce_platform
6.0.1
oracleretail_predictive_application_server
15.0.3
oracleretail_service_backbone
14.1
oracleretail_service_backbone
15.0
oracleretail_service_backbone
16.0
oraclesiebel_ui_framework
18.7
oraclesiebel_ui_framework
18.8
oraclesiebel_ui_framework
18.9
oraclesoa_suite
12.1.3.0.0
oraclesoa_suite
12.2.1.3.0
oraclesoa_suite
12.2.2.0.0
oracletape_library_acsls
8.4
oracletimesten_in-memory_database
11.2.2.8.49
oracleutilities_advanced_spatial_and_operational_analytics
2.7.0.1
oracleutilities_work_and_asset_management
1.9.1.2.12
oracleweblogic_server
10.3.6.0.0
oracleweblogic_server
12.1.3.0.0
oracleweblogic_server
12.2.1.3.0
oracleweblogic_server
12.2.1.4.0
oracleweblogic_server
14.1.1.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache-log4j2
bullseye
2.17.1-1~deb11u1
fixed
jessie
ignored
bullseye (security)
2.17.0-1~deb11u1
fixed
sid
2.19.0-2
fixed
trixie
2.19.0-2
fixed
bookworm
2.19.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache-log4j2
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
ignored
zesty
ignored
yakkety
ignored
xenial
needed
trusty
dne
precise
dne
References