---
id: CVE-2017-5645
title: >-
  In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP
  socket server to receive serialized log events from another application, a
  specially crafted binary payload can be sent that, when deserialized, can
  execute arbitr…
summary: >-
  In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP
  socket server to receive serialized log events from another application, a
  specially crafted binary payload can be sent that, when deserialized, can
  execute arbitr…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: apache
product: log4j
affected:
  - 'log4j >= 2.0, < 2.8.2'
  - oncommand_api_services
  - oncommand_insight
  - oncommand_workflow_automation
  - service_level_manager
  - snapcenter
  - storage_automation_store
  - fuse = 1.0
  - enterprise_linux = 6.0
  - enterprise_linux = 6.7
  - enterprise_linux = 7.0
  - enterprise_linux = 7.3
  - enterprise_linux = 7.4
  - enterprise_linux = 7.5
  - enterprise_linux = 7.6
  - enterprise_linux_desktop = 7.0
  - enterprise_linux_server = 7.0
  - enterprise_linux_server_aus = 7.4
  - enterprise_linux_server_aus = 7.6
  - enterprise_linux_server_eus = 7.4
  - enterprise_linux_server_eus = 7.5
  - enterprise_linux_server_eus = 7.6
  - enterprise_linux_server_tus = 7.4
  - enterprise_linux_server_tus = 7.6
  - enterprise_linux_workstation = 7.0
  - api_gateway = 11.1.2.4.0
  - application_testing_suite = 13.3.0.1
  - autovue_vuelink_integration = 21.0.0
  - autovue_vuelink_integration = 21.0.1
  - banking_platform = 2.6.0
  - banking_platform = 2.6.1
  - banking_platform = 2.6.2
  - bi_publisher = 11.1.1.7.0
  - bi_publisher = 11.1.1.9.0
  - bi_publisher = 12.2.1.3.0
  - bi_publisher = 12.2.1.4.0
  - communications_converged_application_server_-_service_controller = 6.1
  - communications_instant_messaging_server = 10.0.1.3.0
  - 'communications_interactive_session_recorder >= 6.0, <= 6.2'
  - communications_messaging_server < 8.0.2
  - 'communications_network_integrity >= 7.3.2, <= 7.3.6'
  - communications_online_mediation_controller = 6.1
  - communications_pricing_design_center = 11.1
  - communications_pricing_design_center = 12.0
  - communications_service_broker = 6.0
  - communications_webrtc_session_controller < 7.2
  - configuration_manager = 12.1.2.0.2
  - configuration_manager = 12.1.2.0.5
  - endeca_information_discovery_studio = 3.2.0
  - enterprise_data_quality = 12.2.1.3.0
  - enterprise_manager_base_platform = 12.1.0.5
  - enterprise_manager_base_platform = 13.2.0.0
  - enterprise_manager_for_fusion_middleware = 12.1.0.5
  - enterprise_manager_for_fusion_middleware = 13.2.0.0
  - enterprise_manager_for_mysql_database <= 13.2.2.0.0
  - enterprise_manager_for_oracle_database = 12.1.0.8
  - enterprise_manager_for_oracle_database = 13.2.2
  - enterprise_manager_for_peoplesoft = 13.1.1.1
  - enterprise_manager_for_peoplesoft = 13.2.1.1
  - >-
    financial_services_analytical_applications_infrastructure >= 7.3.3.0.0, <=
    7.3.3.0.2
  - >-
    financial_services_analytical_applications_infrastructure >= 8.0.0.0.0, <=
    8.0.7.0.0
  - 'financial_services_behavior_detection_platform >= 8.0.0.0.0, <= 8.0.4.0.0'
  - financial_services_behavior_detection_platform = 6.1.1
  - financial_services_hedge_management_and_ifrs_valuations = 8.0.4
  - financial_services_hedge_management_and_ifrs_valuations = 8.0.5
  - 'financial_services_lending_and_leasing >= 14.1.0, <= 14.8.0'
  - financial_services_lending_and_leasing = 12.5.0
  - financial_services_loan_loss_forecasting_and_provisioning = 8.0.4
  - financial_services_loan_loss_forecasting_and_provisioning = 8.0.5
  - 'financial_services_profitability_management >= 8.0.0.0.0, <= 8.0.7.0.0'
  - financial_services_profitability_management = 6.1.1
  - financial_services_regulatory_reporting_with_agilereporter = 8.0.9.2.0
  - flexcube_investor_servicing = 12.0.4
  - flexcube_investor_servicing = 12.1.0
  - flexcube_investor_servicing = 12.3.0
  - flexcube_investor_servicing = 12.4.0
  - flexcube_investor_servicing = 14.0.0
  - fusion_middleware_mapviewer = 12.2.1.2
  - fusion_middleware_mapviewer = 12.2.1.3
  - goldengate = 12.3.2.1.1
  - goldengate_application_adapters = 12.3.2.1.1
  - identity_analytics = 11.1.1.5.8
  - identity_management_suite = 11.1.2.3.0
  - identity_management_suite = 12.2.1.3.0
  - identity_manager_connector = 9.0
  - in-memory_performance-driven_planning = 12.1
  - in-memory_performance-driven_planning = 12.2
  - 'instantis_enterprisetrack >= 17.1, <= 17.3'
  - insurance_calculation_engine = 10.1.1
  - insurance_calculation_engine = 10.2.1
  - insurance_policy_administration = 10.0
  - insurance_policy_administration = 10.1
  - insurance_policy_administration = 10.2
  - insurance_policy_administration = 11.0
  - insurance_rules_palette = 10.0
  - insurance_rules_palette = 10.1
  - insurance_rules_palette = 10.2
  - insurance_rules_palette = 11.0
  - insurance_rules_palette = 11.1
  - jd_edwards_enterpriseone_tools = 4.0.1.0
patched:
  - log4j 2.8.2
  - communications_messaging_server 8.0.2
  - communications_webrtc_session_controller 7.2
published: '2017-04-17'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:40.790'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-5645'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2019/12/19/2'
    label: security@apache.org
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
    label: security@apache.org
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
    label: security@apache.org
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
    label: security@apache.org
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
    label: security@apache.org
  - url: 'http://www.securityfocus.com/bid/97702'
    label: security@apache.org
  - url: 'http://www.securitytracker.com/id/1040200'
    label: security@apache.org
  - url: 'http://www.securitytracker.com/id/1041294'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:1417'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:1801'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:1802'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2423'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2633'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2635'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2636'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2637'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2638'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2808'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2809'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2810'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2811'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2888'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:2889'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:3244'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:3399'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:3400'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:1545'
    label: security@apache.org
  - url: 'https://issues.apache.org/jira/browse/LOG4J2-1863'
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/0dcca05274d20ef2d72584edcf8c917bbb13dbbd7eb35cae909d02e9%40%3Cdev.logging.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/277b4b5c2b0e06a825ccec565fa65bd671f35a4d58e3e2ec5d0618e1%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/44491fb9cc19acc901f7cff34acb7376619f15638439416e3e14761c%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/479471e6debd608c837b9815b76eab24676657d4444fcfd5ef96d6e6%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/6114ce566200d76e3cc45c521a62c2c5a4eac15738248f58a99f622c%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/84cc4266238e057b95eb95dfd8b29d46a2592e7672c12c92f68b2917%40%3Cannounce.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/8ab32b4c9f1826f20add7c40be08909de9f58a89dc1de9c09953f5ac%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/e8fb7d76a244ee997ba4b217d6171227f7c2521af8c7c5b16cba27bc%40%3Cdev.logging.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/eea03d504b36e8f870e8321d908e1def1addda16adda04327fe7c125%40%3Cdev.logging.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r0831e2e52a390758ce39a6193f82c11c295175adce6e6307de28c287%40%3Cissues.beam.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r18f1c010b554a3a2d761e8ffffd8674fd4747bcbcf16c643d708318c%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r23369fd603eb6d62d3b883a0a28d12052dcbd1d6d531137124cd7f83%40%3Cgithub.beam.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r2ce8d26154bea939536e6cf27ed02d3192bf5c5d04df885a80fe89b3%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r2ff63f210842a3c5e42f03a35d8f3a345134d073c80a04077341c211%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r3784834e80df2f284577a5596340fb84346c91a2dea6a073e65e3397%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r3a85514a518f3080ab1fc2652cfe122c2ccf67cfb32356acb1b08fe8%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r3d666e4e8905157f3c046d31398b04f2bfd4519e31f266de108c6919%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r4b25538be50126194cc646836c718b1a4d8f71bd9c912af5b59134ad%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r61590890edcc64140e0c606954b29a063c3d08a2b41d447256d51a78%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r681b4432d0605f327b68b9f8a42662993e699d04614de4851c35ffd1%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r746fbc3fc13aee292ae6851f7a5080f592fa3a67b983c6887cdb1fc5%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r7bcdc710857725c311b856c0b82cee6207178af5dcde1bd43d289826%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r94b5aae09c4bcff5d06cf641be17b00bd83ba7e10cad737bf16a1b8f%40%3Cgithub.beam.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r9d5c1b558a15d374bd5abd2d3ae3ca7e50e796a0efdcf91e9c5b4cdd%40%3Cgithub.beam.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/ra38785cfc0e7f17f8e24bebf775dd032c033fadcaea29e5bc9fffc60%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/ra9a682bc0a8dff1c5cefdef31c7c25f096d9121207cf2d74e2fc563d%40%3Ccommits.logging.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/raedd12dc24412b3780432bf202a2618a21a727788543e5337a458ead%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rb1b29aee737e1c37fe1d48528cb0febac4f5deed51f5412e6fdfe2bf%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rbfa7a0742be4981a3f9356a23d0e1a5f2e1eabde32a1a3d8e41420f8%40%3Cgithub.beam.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rc1eaed7f7d774d5d02f66e49baced31e04827a1293d61a70bd003ca7%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rca24a281000fb681d7e26e5c031a21eb4b0593a7735f781b53dae4e2%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rcbb79023a7c8494cb389cd3d95420fa9e0d531ece0b780b8c1f99422%40%3Ccommits.doris.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rd5dbeee4808c0f2b9b51479b50de3cc6adb1072c332a200d9107f13e%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rdbd579dc223f06af826d7de340218ee2f80d8b43fa7e4decb2a63f44%40%3Cgithub.beam.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rdec0d8ac1f03e6905b0de2df1d5fcdb98b94556e4f6cccf7519fdb26%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/re8c21ed9dd218c217d242ffa90778428e446b082b5e1c29f567e8374%40%3Cissues.activemq.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rf2567488cfc9212b42e34c6393cfa1c14e30e4838b98dda84d71041f%40%3Cdev.tika.apache.org%3E
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20180726-0002/'
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20181107-0002/'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: security@apache.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: security@apache.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
    label: security@apache.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
    label: security@apache.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2019/12/19/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/97702'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1040200'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1041294'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:1417'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:1801'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:1802'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2423'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2633'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2635'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2636'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2637'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2638'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2808'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2809'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2810'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2811'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2888'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2889'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:3244'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:3399'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:3400'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2019:1545'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://issues.apache.org/jira/browse/LOG4J2-1863'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/0dcca05274d20ef2d72584edcf8c917bbb13dbbd7eb35cae909d02e9%40%3Cdev.logging.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/277b4b5c2b0e06a825ccec565fa65bd671f35a4d58e3e2ec5d0618e1%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/44491fb9cc19acc901f7cff34acb7376619f15638439416e3e14761c%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/479471e6debd608c837b9815b76eab24676657d4444fcfd5ef96d6e6%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/6114ce566200d76e3cc45c521a62c2c5a4eac15738248f58a99f622c%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/84cc4266238e057b95eb95dfd8b29d46a2592e7672c12c92f68b2917%40%3Cannounce.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/8ab32b4c9f1826f20add7c40be08909de9f58a89dc1de9c09953f5ac%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/e8fb7d76a244ee997ba4b217d6171227f7c2521af8c7c5b16cba27bc%40%3Cdev.logging.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/eea03d504b36e8f870e8321d908e1def1addda16adda04327fe7c125%40%3Cdev.logging.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r0831e2e52a390758ce39a6193f82c11c295175adce6e6307de28c287%40%3Cissues.beam.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r18f1c010b554a3a2d761e8ffffd8674fd4747bcbcf16c643d708318c%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r23369fd603eb6d62d3b883a0a28d12052dcbd1d6d531137124cd7f83%40%3Cgithub.beam.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r2ce8d26154bea939536e6cf27ed02d3192bf5c5d04df885a80fe89b3%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r2ff63f210842a3c5e42f03a35d8f3a345134d073c80a04077341c211%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r3784834e80df2f284577a5596340fb84346c91a2dea6a073e65e3397%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r3a85514a518f3080ab1fc2652cfe122c2ccf67cfb32356acb1b08fe8%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r3d666e4e8905157f3c046d31398b04f2bfd4519e31f266de108c6919%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r4b25538be50126194cc646836c718b1a4d8f71bd9c912af5b59134ad%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r61590890edcc64140e0c606954b29a063c3d08a2b41d447256d51a78%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r681b4432d0605f327b68b9f8a42662993e699d04614de4851c35ffd1%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r746fbc3fc13aee292ae6851f7a5080f592fa3a67b983c6887cdb1fc5%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r7bcdc710857725c311b856c0b82cee6207178af5dcde1bd43d289826%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r94b5aae09c4bcff5d06cf641be17b00bd83ba7e10cad737bf16a1b8f%40%3Cgithub.beam.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r9d5c1b558a15d374bd5abd2d3ae3ca7e50e796a0efdcf91e9c5b4cdd%40%3Cgithub.beam.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/ra38785cfc0e7f17f8e24bebf775dd032c033fadcaea29e5bc9fffc60%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/ra9a682bc0a8dff1c5cefdef31c7c25f096d9121207cf2d74e2fc563d%40%3Ccommits.logging.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/raedd12dc24412b3780432bf202a2618a21a727788543e5337a458ead%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rb1b29aee737e1c37fe1d48528cb0febac4f5deed51f5412e6fdfe2bf%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rbfa7a0742be4981a3f9356a23d0e1a5f2e1eabde32a1a3d8e41420f8%40%3Cgithub.beam.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc1eaed7f7d774d5d02f66e49baced31e04827a1293d61a70bd003ca7%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rca24a281000fb681d7e26e5c031a21eb4b0593a7735f781b53dae4e2%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rcbb79023a7c8494cb389cd3d95420fa9e0d531ece0b780b8c1f99422%40%3Ccommits.doris.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rd5dbeee4808c0f2b9b51479b50de3cc6adb1072c332a200d9107f13e%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rdbd579dc223f06af826d7de340218ee2f80d8b43fa7e4decb2a63f44%40%3Cgithub.beam.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rdec0d8ac1f03e6905b0de2df1d5fcdb98b94556e4f6cccf7519fdb26%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/re8c21ed9dd218c217d242ffa90778428e446b082b5e1c29f567e8374%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf2567488cfc9212b42e34c6393cfa1c14e30e4838b98dda84d71041f%40%3Cdev.tika.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20180726-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20181107-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.89792
epssPercentile: 0.9979
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/pimps/CVE-2017-5645'
    - 'https://github.com/HynekPetrak/log4shell-finder'
  nuclei:
    - network/cves/2017/CVE-2017-5645
  checkedAt: '2026-10-08T23:17:21.723Z'
exploitAvailable: true
ingestedAt: '2026-10-08T23:16:47.282Z'
---

## Overview

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

## Affected

- `log4j >= 2.0, < 2.8.2`
- `oncommand_api_services`
- `oncommand_insight`
- `oncommand_workflow_automation`
- `service_level_manager`
- `snapcenter`
- `storage_automation_store`
- `fuse = 1.0`
- `enterprise_linux = 6.0`
- `enterprise_linux = 6.7`
- `enterprise_linux = 7.0`
- `enterprise_linux = 7.3`
- `enterprise_linux = 7.4`
- `enterprise_linux = 7.5`
- `enterprise_linux = 7.6`
- `enterprise_linux_desktop = 7.0`
- `enterprise_linux_server = 7.0`
- `enterprise_linux_server_aus = 7.4`
- `enterprise_linux_server_aus = 7.6`
- `enterprise_linux_server_eus = 7.4`
- `enterprise_linux_server_eus = 7.5`
- `enterprise_linux_server_eus = 7.6`
- `enterprise_linux_server_tus = 7.4`
- `enterprise_linux_server_tus = 7.6`
- `enterprise_linux_workstation = 7.0`
- `api_gateway = 11.1.2.4.0`
- `application_testing_suite = 13.3.0.1`
- `autovue_vuelink_integration = 21.0.0`
- `autovue_vuelink_integration = 21.0.1`
- `banking_platform = 2.6.0`
- `banking_platform = 2.6.1`
- `banking_platform = 2.6.2`
- `bi_publisher = 11.1.1.7.0`
- `bi_publisher = 11.1.1.9.0`
- `bi_publisher = 12.2.1.3.0`
- `bi_publisher = 12.2.1.4.0`
- `communications_converged_application_server_-_service_controller = 6.1`
- `communications_instant_messaging_server = 10.0.1.3.0`
- `communications_interactive_session_recorder >= 6.0, <= 6.2`
- `communications_messaging_server < 8.0.2`
- `communications_network_integrity >= 7.3.2, <= 7.3.6`
- `communications_online_mediation_controller = 6.1`
- `communications_pricing_design_center = 11.1`
- `communications_pricing_design_center = 12.0`
- `communications_service_broker = 6.0`
- `communications_webrtc_session_controller < 7.2`
- `configuration_manager = 12.1.2.0.2`
- `configuration_manager = 12.1.2.0.5`
- `endeca_information_discovery_studio = 3.2.0`
- `enterprise_data_quality = 12.2.1.3.0`
- `enterprise_manager_base_platform = 12.1.0.5`
- `enterprise_manager_base_platform = 13.2.0.0`
- `enterprise_manager_for_fusion_middleware = 12.1.0.5`
- `enterprise_manager_for_fusion_middleware = 13.2.0.0`
- `enterprise_manager_for_mysql_database <= 13.2.2.0.0`
- `enterprise_manager_for_oracle_database = 12.1.0.8`
- `enterprise_manager_for_oracle_database = 13.2.2`
- `enterprise_manager_for_peoplesoft = 13.1.1.1`
- `enterprise_manager_for_peoplesoft = 13.2.1.1`
- `financial_services_analytical_applications_infrastructure >= 7.3.3.0.0, <= 7.3.3.0.2`
- `financial_services_analytical_applications_infrastructure >= 8.0.0.0.0, <= 8.0.7.0.0`
- `financial_services_behavior_detection_platform >= 8.0.0.0.0, <= 8.0.4.0.0`
- `financial_services_behavior_detection_platform = 6.1.1`
- `financial_services_hedge_management_and_ifrs_valuations = 8.0.4`
- `financial_services_hedge_management_and_ifrs_valuations = 8.0.5`
- `financial_services_lending_and_leasing >= 14.1.0, <= 14.8.0`
- `financial_services_lending_and_leasing = 12.5.0`
- `financial_services_loan_loss_forecasting_and_provisioning = 8.0.4`
- `financial_services_loan_loss_forecasting_and_provisioning = 8.0.5`
- `financial_services_profitability_management >= 8.0.0.0.0, <= 8.0.7.0.0`
- `financial_services_profitability_management = 6.1.1`
- `financial_services_regulatory_reporting_with_agilereporter = 8.0.9.2.0`
- `flexcube_investor_servicing = 12.0.4`
- `flexcube_investor_servicing = 12.1.0`
- `flexcube_investor_servicing = 12.3.0`
- `flexcube_investor_servicing = 12.4.0`
- `flexcube_investor_servicing = 14.0.0`
- `fusion_middleware_mapviewer = 12.2.1.2`
- `fusion_middleware_mapviewer = 12.2.1.3`
- `goldengate = 12.3.2.1.1`
- `goldengate_application_adapters = 12.3.2.1.1`
- `identity_analytics = 11.1.1.5.8`
- `identity_management_suite = 11.1.2.3.0`
- `identity_management_suite = 12.2.1.3.0`
- `identity_manager_connector = 9.0`
- `in-memory_performance-driven_planning = 12.1`
- `in-memory_performance-driven_planning = 12.2`
- `instantis_enterprisetrack >= 17.1, <= 17.3`
- `insurance_calculation_engine = 10.1.1`
- `insurance_calculation_engine = 10.2.1`
- `insurance_policy_administration = 10.0`
- `insurance_policy_administration = 10.1`
- `insurance_policy_administration = 10.2`
- `insurance_policy_administration = 11.0`
- `insurance_rules_palette = 10.0`
- `insurance_rules_palette = 10.1`
- `insurance_rules_palette = 10.2`
- `insurance_rules_palette = 11.0`
- `insurance_rules_palette = 11.1`
- `jd_edwards_enterpriseone_tools = 4.0.1.0`

## Remediation

Upgrade past the affected range:

- `log4j 2.8.2`
- `communications_messaging_server 8.0.2`
- `communications_webrtc_session_controller 7.2`
