Versio.io

CVE-2017-5645

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 17-04-2017 11:59
Last modified: - 04-04-2022 06:53
Total changes: - 13

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Low
Attack complexity
Network
Attack vector
High
Availability
High
Confidentiality
High
Integrity
None
Privileges required
Unchanged
Scope
None
User interaction
9.8
Base score
3.9
5.9
Exploitability score
Impact score
 

Verification logic

OR
OR
vendor=apache AND product=log4j AND versionStartIncluding=2.0 AND versionEndExcluding=2.8.2
OR
vendor=netapp AND product=oncommand_api_services AND version=-
vendor=netapp AND product=oncommand_insight AND version=-
vendor=netapp AND product=oncommand_workflow_automation AND version=-
vendor=netapp AND product=snapcenter AND version=-
vendor=netapp AND product=storage_automation_store AND version=-
vendor=netapp AND product=service_level_manager AND version=-
OR
vendor=Red Hat Enterprise Linux AND product=fuse AND version=1.0
vendor=Red Hat Enterprise Linux AND product=enterprise_linux AND version=6.0
vendor=Red Hat Enterprise Linux AND product=enterprise_linux AND version=6.7
vendor=Red Hat Enterprise Linux AND product=enterprise_linux AND version=7.0
vendor=Red Hat Enterprise Linux AND product=enterprise_linux AND version=7.3
vendor=Red Hat Enterprise Linux AND product=enterprise_linux AND version=7.4
vendor=Red Hat Enterprise Linux AND product=enterprise_linux AND version=7.5
vendor=Red Hat Enterprise Linux AND product=enterprise_linux AND version=7.6
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_desktop AND version=7.0
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_server AND version=7.0
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_server_aus AND version=7.4
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_server_aus AND version=7.6
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_server_eus AND version=7.4
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_server_eus AND version=7.5
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_server_eus AND version=7.6
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_server_tus AND version=7.4
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_server_tus AND version=7.6
vendor=Red Hat Enterprise Linux AND product=enterprise_linux_workstation AND version=7.0
OR
vendor=oracle AND product=api_gateway AND version=11.1.2.4.0
vendor=oracle AND product=application_testing_suite AND version=13.3.0.1
vendor=oracle AND product=autovue_vuelink_integration AND version=21.0.0
vendor=oracle AND product=autovue_vuelink_integration AND version=21.0.1
vendor=oracle AND product=banking_platform AND version=2.6.0
vendor=oracle AND product=banking_platform AND version=2.6.1
vendor=oracle AND product=banking_platform AND version=2.6.2
vendor=oracle AND product=bi_publisher AND version=11.1.1.7.0
vendor=oracle AND product=bi_publisher AND version=11.1.1.9.0
vendor=oracle AND product=bi_publisher AND version=12.2.1.3.0
vendor=oracle AND product=bi_publisher AND version=12.2.1.4.0
vendor=oracle AND product=communications_converged_application_server_-_service_controller AND version=6.1
vendor=oracle AND product=communications_instant_messaging_server AND version=10.0.1.3.0
vendor=oracle AND product=communications_interactive_session_recorder AND versionEndIncluding=6.2 AND versionStartIncluding=6.0
vendor=oracle AND product=communications_messaging_server AND versionEndExcluding=8.0.2
vendor=oracle AND product=communications_network_integrity AND versionEndIncluding=7.3.6 AND versionStartIncluding=7.3.2
vendor=oracle AND product=communications_online_mediation_controller AND version=6.1
vendor=oracle AND product=communications_pricing_design_center AND version=11.1
vendor=oracle AND product=communications_pricing_design_center AND version=12.0
vendor=oracle AND product=communications_service_broker AND version=6.0
vendor=oracle AND product=communications_webrtc_session_controller AND versionEndExcluding=7.2
vendor=oracle AND product=configuration_manager AND version=12.1.2.0.2
vendor=oracle AND product=configuration_manager AND version=12.1.2.0.5
vendor=oracle AND product=endeca_information_discovery_studio AND version=3.2.0
vendor=oracle AND product=enterprise_data_quality AND version=12.2.1.3.0
vendor=oracle AND product=enterprise_manager_base_platform AND version=12.1.0.5
vendor=oracle AND product=enterprise_manager_base_platform AND version=13.2.0.0
vendor=oracle AND product=enterprise_manager_for_fusion_middleware AND version=12.1.0.5
vendor=oracle AND product=enterprise_manager_for_fusion_middleware AND version=13.2.0.0
vendor=oracle AND product=enterprise_manager_for_mysql_database AND versionEndIncluding=13.2.2.0.0
vendor=oracle AND product=enterprise_manager_for_oracle_database AND version=12.1.0.8
vendor=oracle AND product=enterprise_manager_for_oracle_database AND version=13.2.2
vendor=oracle AND product=enterprise_manager_for_peoplesoft AND version=13.1.1.1
vendor=oracle AND product=enterprise_manager_for_peoplesoft AND version=13.2.1.1
vendor=oracle AND product=financial_services_analytical_applications_infrastructure AND versionEndIncluding=7.3.3.0.2 AND versionStartIncluding=7.3.3.0.0
vendor=oracle AND product=financial_services_analytical_applications_infrastructure AND versionEndIncluding=8.0.7.0.0 AND versionStartIncluding=8.0.0.0.0
vendor=oracle AND product=financial_services_behavior_detection_platform AND version=6.1.1
vendor=oracle AND product=financial_services_behavior_detection_platform AND versionEndIncluding=8.0.4.0.0 AND versionStartIncluding=8.0.0.0.0
vendor=oracle AND product=financial_services_hedge_management_and_ifrs_valuations AND version=8.0.4
vendor=oracle AND product=financial_services_hedge_management_and_ifrs_valuations AND version=8.0.5
vendor=oracle AND product=financial_services_lending_and_leasing AND version=12.5.0
vendor=oracle AND product=financial_services_lending_and_leasing AND versionEndIncluding=14.8.0 AND versionStartIncluding=14.1.0
vendor=oracle AND product=financial_services_loan_loss_forecasting_and_provisioning AND version=8.0.4
vendor=oracle AND product=financial_services_loan_loss_forecasting_and_provisioning AND version=8.0.5
vendor=oracle AND product=financial_services_profitability_management AND version=6.1.1
vendor=oracle AND product=financial_services_profitability_management AND versionEndIncluding=8.0.7.0.0 AND versionStartIncluding=8.0.0.0.0
vendor=oracle AND product=financial_services_regulatory_reporting_with_agilereporter AND version=8.0.9.2.0
vendor=oracle AND product=flexcube_investor_servicing AND version=12.0.4
vendor=oracle AND product=flexcube_investor_servicing AND version=12.1.0
vendor=oracle AND product=flexcube_investor_servicing AND version=12.3.0
vendor=oracle AND product=flexcube_investor_servicing AND version=12.4.0
vendor=oracle AND product=flexcube_investor_servicing AND version=14.0.0
vendor=oracle AND product=fusion_middleware_mapviewer AND version=12.2.1.2
vendor=oracle AND product=fusion_middleware_mapviewer AND version=12.2.1.3
vendor=oracle AND product=goldengate AND version=12.3.2.1.1
vendor=oracle AND product=goldengate_application_adapters AND version=12.3.2.1.1
vendor=oracle AND product=identity_analytics AND version=11.1.1.5.8
vendor=oracle AND product=identity_management_suite AND version=11.1.2.3.0
vendor=oracle AND product=identity_management_suite AND version=12.2.1.3.0
vendor=oracle AND product=identity_manager_connector AND version=9.0
vendor=oracle AND product=in-memory_performance-driven_planning AND version=12.1
vendor=oracle AND product=in-memory_performance-driven_planning AND version=12.2
vendor=oracle AND product=instantis_enterprisetrack AND versionEndIncluding=17.3 AND versionStartIncluding=17.1
vendor=oracle AND product=insurance_calculation_engine AND version=10.1.1
vendor=oracle AND product=insurance_calculation_engine AND version=10.2.1
vendor=oracle AND product=insurance_policy_administration AND version=10.0
vendor=oracle AND product=insurance_policy_administration AND version=10.1
vendor=oracle AND product=insurance_policy_administration AND version=10.2
vendor=oracle AND product=insurance_policy_administration AND version=11.0
vendor=oracle AND product=insurance_rules_palette AND version=10.0
vendor=oracle AND product=insurance_rules_palette AND version=10.1
vendor=oracle AND product=insurance_rules_palette AND version=10.2
vendor=oracle AND product=insurance_rules_palette AND version=11.0
vendor=oracle AND product=insurance_rules_palette AND version=11.1
vendor=oracle AND product=jd_edwards_enterpriseone_tools AND version=4.0.1.0
vendor=oracle AND product=jd_edwards_enterpriseone_tools AND version=9.2
vendor=oracle AND product=jdeveloper AND version=11.1.1.9.0
vendor=oracle AND product=jdeveloper AND version=12.1.3.0.0
vendor=oracle AND product=jdeveloper AND version=12.2.1.3.0
vendor=oracle AND product=mysql_enterprise_monitor AND versionEndIncluding=3.4.7.4297 AND versionStartIncluding=3.4.0.0
vendor=oracle AND product=mysql_enterprise_monitor AND versionEndIncluding=4.0.4.5235 AND versionStartIncluding=4.0.0.0
vendor=oracle AND product=mysql_enterprise_monitor AND versionEndIncluding=8.0.0.8131 AND versionStartIncluding=8.0.0.0.0
vendor=oracle AND product=peoplesoft_enterprise_fin_install AND version=9.2
vendor=oracle AND product=policy_automation AND version=10.4.7
vendor=oracle AND product=policy_automation AND version=12.1.0
vendor=oracle AND product=policy_automation AND version=12.1.1
vendor=oracle AND product=policy_automation AND version=12.2.0
vendor=oracle AND product=policy_automation AND version=12.2.1
vendor=oracle AND product=policy_automation AND version=12.2.2
vendor=oracle AND product=policy_automation AND version=12.2.3
vendor=oracle AND product=policy_automation AND version=12.2.4
vendor=oracle AND product=policy_automation AND version=12.2.5
vendor=oracle AND product=policy_automation AND version=12.2.6
vendor=oracle AND product=policy_automation AND version=12.2.7
vendor=oracle AND product=policy_automation AND version=12.2.8
vendor=oracle AND product=policy_automation AND version=12.2.9
vendor=oracle AND product=policy_automation AND version=12.2.10
vendor=oracle AND product=policy_automation_connector_for_siebel AND version=10.4.6
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=10.4.7
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.1.0
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.1.1
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.2.0
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.2.1
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.2.2
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.2.3
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.2.4
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.2.5
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.2.6
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.2.7
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.2.8
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.2.9
vendor=oracle AND product=policy_automation_for_mobile_devices AND version=12.2.10
vendor=oracle AND product=primavera_gateway AND versionEndIncluding=16.2.11 AND versionStartIncluding=16.2.0
vendor=oracle AND product=primavera_gateway AND versionEndIncluding=17.12.7 AND versionStartIncluding=17.12.0
vendor=oracle AND product=rapid_planning AND version=12.1
vendor=oracle AND product=rapid_planning AND version=12.2
vendor=oracle AND product=retail_advanced_inventory_planning AND version=14.0
vendor=oracle AND product=retail_advanced_inventory_planning AND version=15.0
vendor=oracle AND product=retail_clearance_optimization_engine AND version=14.0.5
vendor=oracle AND product=retail_extract_transform_and_load AND version=13.0
vendor=oracle AND product=retail_extract_transform_and_load AND version=13.1
vendor=oracle AND product=retail_extract_transform_and_load AND version=13.2
vendor=oracle AND product=retail_extract_transform_and_load AND version=19.0
vendor=oracle AND product=retail_integration_bus AND version=14.0.0
vendor=oracle AND product=retail_integration_bus AND version=14.1.0
vendor=oracle AND product=retail_integration_bus AND version=15.0
vendor=oracle AND product=retail_integration_bus AND version=16.0
vendor=oracle AND product=retail_open_commerce_platform AND version=5.3.0
vendor=oracle AND product=retail_open_commerce_platform AND version=6.0.0
vendor=oracle AND product=retail_open_commerce_platform AND version=6.0.1
vendor=oracle AND product=retail_predictive_application_server AND version=15.0.3
vendor=oracle AND product=retail_service_backbone AND version=14.1
vendor=oracle AND product=retail_service_backbone AND version=15.0
vendor=oracle AND product=retail_service_backbone AND version=16.0
vendor=oracle AND product=siebel_ui_framework AND version=18.7
vendor=oracle AND product=siebel_ui_framework AND version=18.8
vendor=oracle AND product=siebel_ui_framework AND version=18.9
vendor=oracle AND product=soa_suite AND version=12.1.3.0.0
vendor=oracle AND product=soa_suite AND version=12.2.1.3.0
vendor=oracle AND product=soa_suite AND version=12.2.2.0.0
vendor=oracle AND product=tape_library_acsls AND version=8.4
vendor=oracle AND product=timesten_in-memory_database AND version=11.2.2.8.49
vendor=oracle AND product=utilities_advanced_spatial_and_operational_analytics AND version=2.7.0.1
vendor=oracle AND product=utilities_work_and_asset_management AND version=1.9.1.2.12
vendor=oracle AND product=weblogic_server AND version=10.3.6.0.0
vendor=oracle AND product=weblogic_server AND version=12.1.3.0.0
vendor=oracle AND product=weblogic_server AND version=12.2.1.3.0
vendor=oracle AND product=weblogic_server AND version=12.2.1.4.0
vendor=oracle AND product=weblogic_server AND version=14.1.1.0.0
 

Reference

 


Keywords

NVD

 

CVE-2017-5645

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.