CVE-2022-23302

EUVD-2022-0721
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
apachelog4j
1.0.1 ≤
𝑥
≤ 1.2.17
netappsnapmanager
-
netappsnapmanager
-
broadcombrocade_sannav
-
qosreload4j
𝑥
< 1.2.18.1
oracleadvanced_supply_chain_planning
12.1
oracleadvanced_supply_chain_planning
12.2
oraclebusiness_intelligence
5.9.0.0.0
oraclebusiness_intelligence
12.2.1.3.0
oraclebusiness_intelligence
12.2.1.4.0
oraclebusiness_process_management_suite
12.2.1.3.0
oraclebusiness_process_management_suite
12.2.1.4.0
oraclecommunications_eagle_ftp_table_base_retrieval
4.5
oraclecommunications_instant_messaging_server
10.0.1.5.0
oraclecommunications_messaging_server
8.1
oraclecommunications_network_integrity
7.3.6
oraclecommunications_offline_mediation_controller
𝑥
< 12.0.0.4.4
oraclecommunications_offline_mediation_controller
12.0.0.5.0
oraclecommunications_unified_inventory_management
7.4.1
oraclecommunications_unified_inventory_management
7.4.2
oraclee-business_suite_cloud_manager_and_cloud_backup_module
𝑥
< 2.2.1.1.1
oraclee-business_suite_cloud_manager_and_cloud_backup_module
2.2.1.1.1
oracleenterprise_manager_base_platform
13.4.0.0
oracleenterprise_manager_base_platform
13.5.0.0
oraclefinancial_services_revenue_management_and_billing_analytics
2.7.0.0
oraclefinancial_services_revenue_management_and_billing_analytics
2.7.0.1
oraclefinancial_services_revenue_management_and_billing_analytics
2.8.0.0
oraclehealthcare_foundation
8.1.0
oraclehyperion_data_relationship_management
𝑥
< 11.2.8.0
oraclehyperion_infrastructure_technology
𝑥
< 11.2.8.0
oracleidentity_management_suite
12.2.1.3.0
oracleidentity_management_suite
12.2.1.4.0
oracleidentity_manager_connector
11.1.1.5.0
oraclejdeveloper
12.2.1.3.0
oraclemiddleware_common_libraries_and_tools
12.2.1.4.0
oraclemysql_enterprise_monitor
𝑥
≤ 8.0.29
oracletuxedo
12.2.2.0.0
oracleweblogic_server
12.2.1.3.0
oracleweblogic_server
12.2.1.4.0
oracleweblogic_server
14.1.1.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache-log4j1.2
bookworm
1.2.17-11
fixed
bullseye
1.2.17-10+deb11u1
fixed
sid
1.2.17-11
fixed
trixie
1.2.17-11
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache-log4j1.2
bionic
Fixed 1.2.17-8+deb10u1ubuntu0.2
released
focal
Fixed 1.2.17-9ubuntu0.2
released
impish
ignored
jammy
not-affected
kinetic
not-affected
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
needed
xenial
Fixed 1.2.17-7ubuntu1+esm1
released