CVE-2017-5645

Published Apr 17, 2017

Last updated a month ago

Overview

Description
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Source
security@apache.org
NVD status
Modified
Products
log4j, oncommand_api_services, oncommand_insight, oncommand_workflow_automation, service_level_manager, snapcenter, storage_automation_store, fuse, enterprise_linux, enterprise_linux_desktop, enterprise_linux_server, enterprise_linux_server_aus, enterprise_linux_server_eus, enterprise_linux_server_tus, enterprise_linux_workstation, api_gateway, application_testing_suite, autovue_vuelink_integration, banking_platform, bi_publisher, communications_converged_application_server_-_service_controller, communications_instant_messaging_server, communications_interactive_session_recorder, communications_messaging_server, communications_network_integrity, communications_online_mediation_controller, communications_pricing_design_center, communications_service_broker, communications_webrtc_session_controller, configuration_manager, endeca_information_discovery_studio, enterprise_data_quality, enterprise_manager_base_platform, enterprise_manager_for_fusion_middleware, enterprise_manager_for_mysql_database, enterprise_manager_for_oracle_database, enterprise_manager_for_peoplesoft, financial_services_analytical_applications_infrastructure, financial_services_behavior_detection_platform, financial_services_hedge_management_and_ifrs_valuations, financial_services_lending_and_leasing, financial_services_loan_loss_forecasting_and_provisioning, financial_services_profitability_management, financial_services_regulatory_reporting_with_agilereporter, flexcube_investor_servicing, fusion_middleware_mapviewer, goldengate, goldengate_application_adapters, identity_analytics, identity_management_suite, identity_manager_connector, in-memory_performance-driven_planning, instantis_enterprisetrack, insurance_calculation_engine, insurance_policy_administration, insurance_rules_palette, jd_edwards_enterpriseone_tools, jdeveloper, mysql_enterprise_monitor, peoplesoft_enterprise_fin_install, policy_automation, policy_automation_connector_for_siebel, policy_automation_for_mobile_devices, primavera_gateway, rapid_planning, retail_advanced_inventory_planning, retail_clearance_optimization_engine, retail_extract_transform_and_load, retail_integration_bus, retail_open_commerce_platform, retail_predictive_application_server, retail_service_backbone, siebel_ui_framework, soa_suite, tape_library_acsls, timesten_in-memory_database, utilities_advanced_spatial_and_operational_analytics, utilities_work_and_asset_management, weblogic_server

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

CVSS 2.0

Type
Primary
Base score
7.5
Impact score
6.4
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-502

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.