CVE-2017-5645

critical
Published 2017-04-17 ยท Modified 2024-03-14
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.8

Description

Deserialization of Untrusted Data in Log4j

Predictions

Exploit likelihood
97%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

redhat Red Hat Affected 7 releases
VersionStatusFixed in
7.6 Affected โ€”
7.5 Affected โ€”
7.4 Affected โ€”
7.3 Affected โ€”
7.0 Affected โ€”
6.7 Affected โ€”
6.0 Affected โ€”
suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.7-2
sid Fixed 2.7-2
forky Fixed 2.7-2
bullseye Fixed 2.7-2
bookworm Fixed 2.7-2

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.logging.log4j:log4j>=2.0,<2.8.22.8.2
java Mavenorg.apache.logging.log4j:log4j-core>=2.0,<2.8.22.8.2

Application impact

VendorProductVersionsFixed
apache apachelog4j{"startIncluding":"2.0","endExcluding":"2.8.2"}2.8.2
netapponcommand_api_services-
netapponcommand_insight-
netapponcommand_workflow_automation-
netappservice_level_manager-
netappsnapcenter-
netappstorage_automation_store-
redhat redhatfuse1.0
oracle oracleapi_gateway11.1.2.4.0
oracle oracleapplication_testing_suite13.3.0.1
oracle oracleautovue_vuelink_integration21.0.0
oracle oracleautovue_vuelink_integration21.0.1
oracle oraclebanking_platform2.6.0
oracle oraclebanking_platform2.6.1
oracle oraclebanking_platform2.6.2
oracle oraclebi_publisher11.1.1.7.0
oracle oraclebi_publisher11.1.1.9.0
oracle oraclebi_publisher12.2.1.3.0
oracle oraclebi_publisher12.2.1.4.0
oracle oraclecommunications_converged_application_server_-_service_controller6.1
oracle oraclecommunications_instant_messaging_server10.0.1.3.0
oracle oraclecommunications_interactive_session_recorder{"startIncluding":"6.0","endIncluding":"6.2"}
oracle oraclecommunications_messaging_server{"endExcluding":"8.0.2"}8.0.2
oracle oraclecommunications_network_integrity{"startIncluding":"7.3.2","endIncluding":"7.3.6"}
oracle oraclecommunications_online_mediation_controller6.1
oracle oraclecommunications_pricing_design_center11.1
oracle oraclecommunications_pricing_design_center12.0
oracle oraclecommunications_service_broker6.0
oracle oraclecommunications_webrtc_session_controller{"endExcluding":"7.2"}7.2
oracle oracleconfiguration_manager12.1.2.0.2
oracle oracleconfiguration_manager12.1.2.0.5
oracle oracleendeca_information_discovery_studio3.2.0
oracle oracleenterprise_data_quality12.2.1.3.0
oracle oracleenterprise_manager_base_platform12.1.0.5
oracle oracleenterprise_manager_base_platform13.2.0.0
oracle oracleenterprise_manager_for_fusion_middleware12.1.0.5
oracle oracleenterprise_manager_for_fusion_middleware13.2.0.0
oracle oracleenterprise_manager_for_mysql_database{"endIncluding":"13.2.2.0.0"}
oracle oracleenterprise_manager_for_oracle_database12.1.0.8
oracle oracleenterprise_manager_for_oracle_database13.2.2
oracle oracleenterprise_manager_for_peoplesoft13.1.1.1
oracle oracleenterprise_manager_for_peoplesoft13.2.1.1
oracle oracleretail_extract_transform_and_load13.2
oracle oraclefinancial_services_analytical_applications_infrastructure{"startIncluding":"7.3.3.0.0","endIncluding":"7.3.3.0.2"}
oracle oraclefinancial_services_behavior_detection_platform{"startIncluding":"8.0.0.0.0","endIncluding":"8.0.4.0.0"}
oracle oraclefinancial_services_behavior_detection_platform6.1.1
oracle oraclefinancial_services_hedge_management_and_ifrs_valuations8.0.4
oracle oraclefinancial_services_hedge_management_and_ifrs_valuations8.0.5
oracle oraclefinancial_services_lending_and_leasing{"startIncluding":"14.1.0","endIncluding":"14.8.0"}
oracle oraclefinancial_services_lending_and_leasing12.5.0
oracle oraclefinancial_services_loan_loss_forecasting_and_provisioning8.0.4
oracle oraclefinancial_services_loan_loss_forecasting_and_provisioning8.0.5
oracle oraclefinancial_services_profitability_management{"startIncluding":"8.0.0.0.0","endIncluding":"8.0.7.0.0"}
oracle oraclefinancial_services_profitability_management6.1.1
oracle oraclefinancial_services_regulatory_reporting_with_agilereporter8.0.9.2.0
oracle oracleflexcube_investor_servicing12.0.4
oracle oracleflexcube_investor_servicing12.1.0
oracle oracleflexcube_investor_servicing12.3.0
oracle oracleflexcube_investor_servicing12.4.0
oracle oracleflexcube_investor_servicing14.0.0
oracle oraclefusion_middleware_mapviewer12.2.1.2
oracle oraclefusion_middleware_mapviewer12.2.1.3
oracle oraclegoldengate12.3.2.1.1
oracle oraclegoldengate_application_adapters12.3.2.1.1
oracle oracleidentity_analytics11.1.1.5.8
oracle oracleidentity_management_suite11.1.2.3.0
oracle oracleidentity_management_suite12.2.1.3.0
oracle oracleidentity_manager_connector9.0
oracle oraclein-memory_performance-driven_planning12.1
oracle oraclein-memory_performance-driven_planning12.2
oracle oracleinstantis_enterprisetrack{"startIncluding":"17.1","endIncluding":"17.3"}
oracle oracleinsurance_calculation_engine10.1.1
oracle oracleinsurance_calculation_engine10.2.1
oracle oracleinsurance_policy_administration10.0
oracle oracleinsurance_policy_administration10.1
oracle oracleinsurance_policy_administration10.2
oracle oracleinsurance_policy_administration11.0
oracle oracleinsurance_rules_palette10.0
oracle oracleinsurance_rules_palette10.1
oracle oracleinsurance_rules_palette10.2
oracle oracleinsurance_rules_palette11.0
oracle oracleinsurance_rules_palette11.1
oracle oraclejd_edwards_enterpriseone_tools4.0.1.0
oracle oraclejd_edwards_enterpriseone_tools9.2
oracle oraclejdeveloper11.1.1.9.0
oracle oraclejdeveloper12.1.3.0.0
oracle oraclejdeveloper12.2.1.3.0
oracle oraclemysql_enterprise_monitor{"startIncluding":"3.4.0.0","endIncluding":"3.4.7.4297"}
oracle oraclepeoplesoft_enterprise_fin_install9.2
oracle oraclepolicy_automation10.4.7
oracle oraclepolicy_automation12.1.0
oracle oraclepolicy_automation12.1.1
oracle oraclepolicy_automation12.2.0
oracle oraclepolicy_automation12.2.1
oracle oraclepolicy_automation12.2.2
oracle oraclepolicy_automation12.2.3
oracle oraclepolicy_automation12.2.4
oracle oraclepolicy_automation12.2.5
oracle oraclepolicy_automation12.2.6
oracle oraclepolicy_automation12.2.7
oracle oraclepolicy_automation12.2.8
oracle oraclepolicy_automation12.2.9
oracle oraclepolicy_automation12.2.10
oracle oraclepolicy_automation_connector_for_siebel10.4.6
oracle oraclepolicy_automation_for_mobile_devices10.4.7
oracle oraclepolicy_automation_for_mobile_devices12.1.0
oracle oraclepolicy_automation_for_mobile_devices12.1.1
oracle oraclepolicy_automation_for_mobile_devices12.2.0
oracle oraclepolicy_automation_for_mobile_devices12.2.1
oracle oraclepolicy_automation_for_mobile_devices12.2.2
oracle oraclepolicy_automation_for_mobile_devices12.2.3
oracle oraclepolicy_automation_for_mobile_devices12.2.4
oracle oraclepolicy_automation_for_mobile_devices12.2.5
oracle oraclepolicy_automation_for_mobile_devices12.2.6
oracle oraclepolicy_automation_for_mobile_devices12.2.7
oracle oraclepolicy_automation_for_mobile_devices12.2.8
oracle oraclepolicy_automation_for_mobile_devices12.2.9
oracle oraclepolicy_automation_for_mobile_devices12.2.10
oracle oracleprimavera_gateway{"startIncluding":"16.2.0","endIncluding":"16.2.11"}
oracle oraclerapid_planning12.1
oracle oraclerapid_planning12.2
oracle oracleretail_advanced_inventory_planning14.0
oracle oracleretail_advanced_inventory_planning15.0
oracle oracleretail_clearance_optimization_engine14.0.5
oracle oracleretail_extract_transform_and_load13.0
oracle oracleretail_extract_transform_and_load13.1
oracle oracleretail_extract_transform_and_load19.0
oracle oracleretail_integration_bus14.0.0
oracle oracleretail_integration_bus14.1.0
oracle oracleretail_integration_bus15.0
oracle oracleretail_integration_bus16.0
oracle oracleretail_open_commerce_platform5.3.0
oracle oracleretail_open_commerce_platform6.0.0
oracle oracleretail_open_commerce_platform6.0.1
oracle oracleretail_predictive_application_server15.0.3
oracle oracleretail_service_backbone14.1
oracle oracleretail_service_backbone15.0
oracle oracleretail_service_backbone16.0
oracle oraclesiebel_ui_framework18.7
oracle oraclesiebel_ui_framework18.8
oracle oraclesiebel_ui_framework18.9
oracle oraclesoa_suite12.1.3.0.0
oracle oraclesoa_suite12.2.1.3.0
oracle oraclesoa_suite12.2.2.0.0
oracle oracletape_library_acsls8.4
oracle oracletimesten_in-memory_database11.2.2.8.49
oracle oracleutilities_advanced_spatial_and_operational_analytics2.7.0.1
oracle oracleutilities_work_and_asset_management1.9.1.2.12
oracle oracleweblogic_server10.3.6.0.0
oracle oracleweblogic_server12.1.3.0.0
oracle oracleweblogic_server12.2.1.3.0
oracle oracleweblogic_server12.2.1.4.0
oracle oracleweblogic_server14.1.1.0.0

References

CWEs

CWE-502

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.