Vulnerability Description
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Log4J | >= 2.0, < 2.8.2 |
| Netapp | Oncommand Api Services | - |
| Netapp | Oncommand Insight | - |
| Netapp | Oncommand Workflow Automation | - |
| Netapp | Service Level Manager | - |
| Netapp | Snapcenter | - |
| Netapp | Storage Automation Store | - |
| Redhat | Fuse | 1.0 |
| Redhat | Enterprise Linux | 6.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.4 |
| Redhat | Enterprise Linux Server Tus | 7.4 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Oracle | Api Gateway | 11.1.2.4.0 |
| Oracle | Application Testing Suite | 13.3.0.1 |
| Oracle | Autovue Vuelink Integration | 21.0.0 |
| Oracle | Banking Platform | 2.6.0 |
| Oracle | Bi Publisher | 11.1.1.7.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2019/12/19/2Mailing ListThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlPatchThird Party Advisory
- http://www.securityfocus.com/bid/97702Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040200Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041294Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1417Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1801Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1802Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2423Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2633Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2635Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2636Third Party Advisory
FAQ
What is CVE-2017-5645?
CVE-2017-5645 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, ...
How severe is CVE-2017-5645?
CVE-2017-5645 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-5645?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Log4J, Netapp Oncommand Api Services, Netapp Oncommand Insight, Netapp Oncommand Workflow Automation, Netapp Service Level Manager.