CVE-2017-5645Critical· 9.8▾ AbyssalPoC availableIn Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitr…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 18 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
90%
2 GitHub repos · Nuclei ×1 (last check)
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
log4j >= 2.0, < 2.8.2oncommand_api_servicesoncommand_insightoncommand_workflow_automationservice_level_managersnapcenterstorage_automation_storefuse = 1.0enterprise_linux = 6.0enterprise_linux = 6.7enterprise_linux = 7.0enterprise_linux = 7.3enterprise_linux = 7.4enterprise_linux = 7.5enterprise_linux = 7.6enterprise_linux_desktop = 7.0enterprise_linux_server = 7.0enterprise_linux_server_aus = 7.4enterprise_linux_server_aus = 7.6enterprise_linux_server_eus = 7.4enterprise_linux_server_eus = 7.5enterprise_linux_server_eus = 7.6enterprise_linux_server_tus = 7.4enterprise_linux_server_tus = 7.6enterprise_linux_workstation = 7.0api_gateway = 11.1.2.4.0application_testing_suite = 13.3.0.1autovue_vuelink_integration = 21.0.0autovue_vuelink_integration = 21.0.1banking_platform = 2.6.0banking_platform = 2.6.1banking_platform = 2.6.2bi_publisher = 11.1.1.7.0bi_publisher = 11.1.1.9.0bi_publisher = 12.2.1.3.0bi_publisher = 12.2.1.4.0communications_converged_application_server_-_service_controller = 6.1communications_instant_messaging_server = 10.0.1.3.0communications_interactive_session_recorder >= 6.0, <= 6.2communications_messaging_server < 8.0.2communications_network_integrity >= 7.3.2, <= 7.3.6communications_online_mediation_controller = 6.1communications_pricing_design_center = 11.1communications_pricing_design_center = 12.0communications_service_broker = 6.0communications_webrtc_session_controller < 7.2configuration_manager = 12.1.2.0.2configuration_manager = 12.1.2.0.5endeca_information_discovery_studio = 3.2.0enterprise_data_quality = 12.2.1.3.0enterprise_manager_base_platform = 12.1.0.5enterprise_manager_base_platform = 13.2.0.0enterprise_manager_for_fusion_middleware = 12.1.0.5enterprise_manager_for_fusion_middleware = 13.2.0.0enterprise_manager_for_mysql_database <= 13.2.2.0.0enterprise_manager_for_oracle_database = 12.1.0.8enterprise_manager_for_oracle_database = 13.2.2enterprise_manager_for_peoplesoft = 13.1.1.1enterprise_manager_for_peoplesoft = 13.2.1.1financial_services_analytical_applications_infrastructure >= 7.3.3.0.0, <= 7.3.3.0.2financial_services_analytical_applications_infrastructure >= 8.0.0.0.0, <= 8.0.7.0.0financial_services_behavior_detection_platform >= 8.0.0.0.0, <= 8.0.4.0.0financial_services_behavior_detection_platform = 6.1.1financial_services_hedge_management_and_ifrs_valuations = 8.0.4financial_services_hedge_management_and_ifrs_valuations = 8.0.5financial_services_lending_and_leasing >= 14.1.0, <= 14.8.0financial_services_lending_and_leasing = 12.5.0financial_services_loan_loss_forecasting_and_provisioning = 8.0.4financial_services_loan_loss_forecasting_and_provisioning = 8.0.5financial_services_profitability_management >= 8.0.0.0.0, <= 8.0.7.0.0financial_services_profitability_management = 6.1.1financial_services_regulatory_reporting_with_agilereporter = 8.0.9.2.0flexcube_investor_servicing = 12.0.4flexcube_investor_servicing = 12.1.0flexcube_investor_servicing = 12.3.0flexcube_investor_servicing = 12.4.0flexcube_investor_servicing = 14.0.0fusion_middleware_mapviewer = 12.2.1.2fusion_middleware_mapviewer = 12.2.1.3goldengate = 12.3.2.1.1goldengate_application_adapters = 12.3.2.1.1identity_analytics = 11.1.1.5.8identity_management_suite = 11.1.2.3.0identity_management_suite = 12.2.1.3.0identity_manager_connector = 9.0in-memory_performance-driven_planning = 12.1in-memory_performance-driven_planning = 12.2instantis_enterprisetrack >= 17.1, <= 17.3insurance_calculation_engine = 10.1.1insurance_calculation_engine = 10.2.1insurance_policy_administration = 10.0insurance_policy_administration = 10.1insurance_policy_administration = 10.2insurance_policy_administration = 11.0insurance_rules_palette = 10.0insurance_rules_palette = 10.1insurance_rules_palette = 10.2insurance_rules_palette = 11.0insurance_rules_palette = 11.1jd_edwards_enterpriseone_tools = 4.0.1.0Upgrade past the affected range:
log4j 2.8.2communications_messaging_server 8.0.2communications_webrtc_session_controller 7.2Connected by shared product, vendor, weakness, or advisory.
CVE-2020-9484High· 7.0When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…
CVE-2021-25329High· 7.0The fix for CVE-2020-9484 was incomplete
CVE-2020-36180High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36179High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36184High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
CVE-2020-35728High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/jav…