HIGH · 8.8

CVE-2022-23302

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service...

Vulnerability Description

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ApacheLog4J>= 1.0.1, <= 1.2.17
NetappSnapmanager-
BroadcomBrocade Sannav-
QosReload4J< 1.2.18.1
OracleAdvanced Supply Chain Planning12.1
OracleBusiness Intelligence5.9.0.0.0
OracleBusiness Process Management Suite12.2.1.3.0
OracleCommunications Eagle Ftp Table Base Retrieval4.5
OracleCommunications Instant Messaging Server10.0.1.5.0
OracleCommunications Messaging Server8.1
OracleCommunications Network Integrity7.3.6
OracleCommunications Offline Mediation Controller< 12.0.0.4.4
OracleCommunications Unified Inventory Management7.4.1
OracleE-Business Suite Cloud Manager And Cloud Backup Module< 2.2.1.1.1
OracleEnterprise Manager Base Platform13.4.0.0
OracleFinancial Services Revenue Management And Billing Analytics2.7.0.0
OracleHealthcare Foundation8.1.0
OracleHyperion Data Relationship Management< 11.2.8.0
OracleHyperion Infrastructure Technology< 11.2.8.0
OracleIdentity Management Suite12.2.1.3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-23302?

CVE-2022-23302 is a vulnerability with a CVSS score of 8.8 (HIGH). JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service...

How severe is CVE-2022-23302?

CVE-2022-23302 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-23302?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Log4J, Netapp Snapmanager, Broadcom Brocade Sannav, Qos Reload4J, Oracle Advanced Supply Chain Planning.