CVE-2019-17571

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
apachelog4j
𝑥
≤ 1.2.17
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
canonicalubuntu_linux
18.04
opensuseleap
15.1
netapponcommand_system_manager
3.0 ≤
𝑥
≤ 3.1.3
netapponcommand_workflow_automation
-
oracleapplication_testing_suite
13.3.0.1
oraclecommunications_network_integrity
7.3.2 ≤
𝑥
≤ 7.3.6
oracleendeca_information_discovery_studio
3.2.0
oraclefinancial_services_lending_and_leasing
14.1.0 ≤
𝑥
≤ 14.8.0
oraclefinancial_services_lending_and_leasing
12.5.0
oraclemysql_enterprise_monitor
𝑥
≤ 8.0.29
oracleprimavera_gateway
16.2 ≤
𝑥
≤ 16.2.11
oracleprimavera_gateway
17.12.0 ≤
𝑥
≤ 17.12.7
oraclerapid_planning
12.1
oraclerapid_planning
12.2
oracleretail_extract_transform_and_load
19.0
oracleretail_service_backbone
14.1
oracleretail_service_backbone
15.0
oracleretail_service_backbone
16.0
oracleweblogic_server
10.3.6.0.0
oracleweblogic_server
12.1.3.0.0
oracleweblogic_server
12.2.1.3.0
oracleweblogic_server
12.2.1.4.0
oracleweblogic_server
14.1.1.0.0
apachebookkeeper
𝑥
< 4.14.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache-log4j1.2
bullseye
1.2.17-10+deb11u1
fixed
sid
1.2.17-11
fixed
trixie
1.2.17-11
fixed
bookworm
1.2.17-11
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache-log4j1.2
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
ignored
disco
ignored
bionic
Fixed 1.2.17-8+deb10u1build0.18.04.1
released
xenial
Fixed 1.2.17-7ubuntu1+esm1
released
trusty
needed
References