CVE-2019-17571

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
apachelog4j
𝑥
≤ 1.2.17
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
canonicalubuntu_linux
18.04
opensuseleap
15.1
netapponcommand_system_manager
3.0 ≤
𝑥
≤ 3.1.3
netapponcommand_workflow_automation
-
oracleapplication_testing_suite
13.3.0.1
oraclecommunications_network_integrity
7.3.2 ≤
𝑥
≤ 7.3.6
oracleendeca_information_discovery_studio
3.2.0
oraclefinancial_services_lending_and_leasing
14.1.0 ≤
𝑥
≤ 14.8.0
oraclefinancial_services_lending_and_leasing
12.5.0
oraclemysql_enterprise_monitor
𝑥
≤ 8.0.29
oracleprimavera_gateway
16.2 ≤
𝑥
≤ 16.2.11
oracleprimavera_gateway
17.12.0 ≤
𝑥
≤ 17.12.7
oraclerapid_planning
12.1
oraclerapid_planning
12.2
oracleretail_extract_transform_and_load
19.0
oracleretail_service_backbone
14.1
oracleretail_service_backbone
15.0
oracleretail_service_backbone
16.0
oracleweblogic_server
10.3.6.0.0
oracleweblogic_server
12.1.3.0.0
oracleweblogic_server
12.2.1.3.0
oracleweblogic_server
12.2.1.4.0
oracleweblogic_server
14.1.1.0.0
apachebookkeeper
𝑥
< 4.14.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache-log4j1.2
bookworm
1.2.17-11
fixed
bullseye
1.2.17-10+deb11u1
fixed
sid
1.2.17-11
fixed
trixie
1.2.17-11
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache-log4j1.2
bionic
Fixed 1.2.17-8+deb10u1build0.18.04.1
released
disco
ignored
eoan
ignored
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
needed
xenial
Fixed 1.2.17-7ubuntu1+esm1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
log4j
suse enterprise desktop 15 SP4
2.17.1-4.20.1
fixed
suse enterprise desktop 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise desktop 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise desktop 15 SP7
2.17.2-150200.4.27.45
fixed
suse enterprise sap 15 SP4
2.17.1-4.20.1
fixed
suse enterprise sap 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise sap 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise sap 15 SP7
2.17.2-150200.4.27.45
fixed
suse enterprise server 15 SP4
2.17.1-4.20.1
fixed
suse enterprise server 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise server 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise server 15 SP7
2.17.2-150200.4.27.45
fixed
log4j-javadoc
suse enterprise desktop 15 SP4
2.17.1-4.20.1
fixed
suse enterprise desktop 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise desktop 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise desktop 15 SP7
2.17.2-150200.4.27.45
fixed
suse enterprise sap 15 SP4
2.17.1-4.20.1
fixed
suse enterprise sap 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise sap 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise sap 15 SP7
2.17.2-150200.4.27.45
fixed
suse enterprise server 15 SP4
2.17.1-4.20.1
fixed
suse enterprise server 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise server 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise server 15 SP7
2.17.2-150200.4.27.45
fixed
log4j-jcl
suse enterprise desktop 15 SP4
2.17.1-4.20.1
fixed
suse enterprise desktop 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise desktop 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise desktop 15 SP7
2.17.2-150200.4.27.45
fixed
suse enterprise sap 15 SP4
2.17.1-4.20.1
fixed
suse enterprise sap 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise sap 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise sap 15 SP7
2.17.2-150200.4.27.45
fixed
suse enterprise server 15 SP4
2.17.1-4.20.1
fixed
suse enterprise server 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise server 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise server 15 SP7
2.17.2-150200.4.27.45
fixed
log4j-slf4j
suse enterprise desktop 15 SP4
2.17.1-4.20.1
fixed
suse enterprise desktop 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise desktop 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise desktop 15 SP7
2.17.2-150200.4.27.45
fixed
suse enterprise sap 15 SP4
2.17.1-4.20.1
fixed
suse enterprise sap 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise sap 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise sap 15 SP7
2.17.2-150200.4.27.45
fixed
suse enterprise server 15 SP4
2.17.1-4.20.1
fixed
suse enterprise server 15 SP5
2.17.2-150200.4.24.13
fixed
suse enterprise server 15 SP6
2.17.2-150200.4.27.45
fixed
suse enterprise server 15 SP7
2.17.2-150200.4.27.45
fixed
log4j12
suse enterprise desktop 15 SP4
1.2.17-4.9.1
fixed
suse enterprise desktop 15 SP5
1.2.17-4.9.1
fixed
suse enterprise desktop 15 SP6
1.2.17-4.9.1
fixed
suse enterprise desktop 15 SP7
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP4
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP5
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP6
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP7
1.2.17-4.9.1
fixed
suse enterprise server 15 SP4
1.2.17-4.9.1
fixed
suse enterprise server 15 SP5
1.2.17-4.9.1
fixed
suse enterprise server 15 SP6
1.2.17-4.9.1
fixed
suse enterprise server 15 SP7
1.2.17-4.9.1
fixed
log4j12-javadoc
suse enterprise desktop 15 SP2
1.2.17-2.26
fixed
suse enterprise desktop 15 SP3
1.2.17-2.26
fixed
suse enterprise desktop 15 SP4
1.2.17-4.9.1
fixed
suse enterprise desktop 15 SP5
1.2.17-4.9.1
fixed
suse enterprise desktop 15 SP6
1.2.17-4.9.1
fixed
suse enterprise desktop 15 SP7
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP2
1.2.17-2.26
fixed
suse enterprise sap 15 SP3
1.2.17-2.26
fixed
suse enterprise sap 15 SP4
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP5
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP6
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP7
1.2.17-4.9.1
fixed
suse enterprise server 15 SP2
1.2.17-2.26
fixed
suse enterprise server 15 SP3
1.2.17-2.26
fixed
suse enterprise server 15 SP4
1.2.17-4.9.1
fixed
suse enterprise server 15 SP5
1.2.17-4.9.1
fixed
suse enterprise server 15 SP6
1.2.17-4.9.1
fixed
suse enterprise server 15 SP7
1.2.17-4.9.1
fixed
log4j12-manual
suse enterprise desktop 15 SP2
1.2.17-2.26
fixed
suse enterprise desktop 15 SP3
1.2.17-2.26
fixed
suse enterprise desktop 15 SP4
1.2.17-4.9.1
fixed
suse enterprise desktop 15 SP5
1.2.17-4.9.1
fixed
suse enterprise desktop 15 SP6
1.2.17-4.9.1
fixed
suse enterprise desktop 15 SP7
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP2
1.2.17-2.26
fixed
suse enterprise sap 15 SP3
1.2.17-2.26
fixed
suse enterprise sap 15 SP4
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP5
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP6
1.2.17-4.9.1
fixed
suse enterprise sap 15 SP7
1.2.17-4.9.1
fixed
suse enterprise server 15 SP2
1.2.17-2.26
fixed
suse enterprise server 15 SP3
1.2.17-2.26
fixed
suse enterprise server 15 SP4
1.2.17-4.9.1
fixed
suse enterprise server 15 SP5
1.2.17-4.9.1
fixed
suse enterprise server 15 SP6
1.2.17-4.9.1
fixed
suse enterprise server 15 SP7
1.2.17-4.9.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
log4j
RHEL 7
0:1.2.17-16.el7_4
fixed
log4j-javadoc
RHEL 7
0:1.2.17-16.el7_4
fixed
log4j-manual
RHEL 7
0:1.2.17-16.el7_4
fixed
References