CVE-2022-23305

critical
Published 2022-01-18 ยท Modified 2022-01-26
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.8

Description

RHSA-2022:0290: parfait:0.5 security update (Important)

Predictions

Exploit likelihood
97%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
8 Fixed uom-lib-1.0.1-6.module_el8.5.0+2610+de2b8c0b.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.2.17-11
sid Fixed 1.2.17-11
forky Fixed 1.2.17-11
bullseye Fixed 1.2.17-10+deb11u1
bookworm Fixed 1.2.17-11
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”

Package impact

EcosystemPackageVulnerableFixed
java Mavenlog4j:log4j<=1.2.17
java Mavenorg.zenframework.z8.dependencies.commons:log4j-1.2.17<=2.0

Application impact

VendorProductVersionsFixed
apache apachelog4j{"startIncluding":"1.2","endIncluding":"1.2.17"}
netappsnapmanager-
vmware broadcombrocade_sannav-
qosreload4j{"endExcluding":"1.2.18.2"}1.2.18.2
oracle oracleadvanced_supply_chain_planning12.1
oracle oracleadvanced_supply_chain_planning12.2
oracle oraclebusiness_intelligence5.9.0.0.0
oracle oraclebusiness_intelligence12.2.1.3.0
oracle oraclebusiness_intelligence12.2.1.4.0
oracle oraclebusiness_process_management_suite12.2.1.3.0
oracle oraclebusiness_process_management_suite12.2.1.4.0
oracle oraclecommunications_eagle_ftp_table_base_retrieval4.5
oracle oraclecommunications_instant_messaging_server10.0.1.5.0
oracle oraclecommunications_messaging_server8.1
oracle oraclecommunications_network_integrity7.3.6
apache apachelog4j{"startIncluding":"1.2","endIncluding":"1.2.17"}
netappsnapmanager-
vmware broadcombrocade_sannav-
qosreload4j{"endExcluding":"1.2.18.2"}1.2.18.2
oracle oracleadvanced_supply_chain_planning12.1
oracle oracleadvanced_supply_chain_planning12.2
oracle oraclebusiness_intelligence5.9.0.0.0
oracle oraclebusiness_intelligence12.2.1.3.0
oracle oraclebusiness_intelligence12.2.1.4.0
oracle oraclebusiness_process_management_suite12.2.1.3.0
oracle oraclebusiness_process_management_suite12.2.1.4.0
oracle oraclecommunications_eagle_ftp_table_base_retrieval4.5
oracle oraclecommunications_instant_messaging_server10.0.1.5.0
oracle oraclecommunications_messaging_server8.1
oracle oraclecommunications_network_integrity7.3.6
oracle oraclecommunications_offline_mediation_controller{"endExcluding":"12.0.0.4.4"}12.0.0.4.4
oracle oraclecommunications_offline_mediation_controller12.0.0.5.0
oracle oraclecommunications_unified_inventory_management7.4.1
oracle oraclecommunications_unified_inventory_management7.4.2
oracle oraclee-business_suite_cloud_manager_and_cloud_backup_module{"endExcluding":"2.2.1.1.1"}2.2.1.1.1
oracle oraclee-business_suite_cloud_manager_and_cloud_backup_module2.2.1.1.1
oracle oraclee-business_suite_information_discovery{"startIncluding":"12.2.3","endIncluding":"12.2.11"}
oracle oracleenterprise_manager_base_platform13.4.0.0
oracle oracleenterprise_manager_base_platform13.5.0.0
oracle oraclefinancial_services_revenue_management_and_billing_analytics2.7.0.0
oracle oraclefinancial_services_revenue_management_and_billing_analytics2.7.0.1
oracle oraclefinancial_services_revenue_management_and_billing_analytics2.8.0.0
oracle oraclehealthcare_foundation8.1.0
oracle oraclehyperion_data_relationship_management{"endExcluding":"11.2.8.0"}11.2.8.0
oracle oraclehyperion_infrastructure_technology{"endExcluding":"11.2.8.0"}11.2.8.0
oracle oracleidentity_management_suite12.2.1.3.0
oracle oracleidentity_management_suite12.2.1.4.0
oracle oracleidentity_manager_connector11.1.1.5.0
oracle oraclejdeveloper12.2.1.3.0
oracle oraclemiddleware_common_libraries_and_tools12.2.1.4.0
oracle oraclemysql_enterprise_monitor{"endIncluding":"8.0.29"}
oracle oracleretail_extract_transform_and_load13.2.5
oracle oracletuxedo12.2.2.0.0
oracle oracleweblogic_server12.2.1.3.0
oracle oracleweblogic_server12.2.1.4.0
oracle oracleweblogic_server14.1.1.0.0
oracle oraclecommunications_offline_mediation_controller{"endExcluding":"12.0.0.4.4"}12.0.0.4.4
oracle oraclecommunications_offline_mediation_controller12.0.0.5.0
oracle oraclecommunications_unified_inventory_management7.4.1
oracle oraclecommunications_unified_inventory_management7.4.2
oracle oraclee-business_suite_cloud_manager_and_cloud_backup_module{"endExcluding":"2.2.1.1.1"}2.2.1.1.1
oracle oraclee-business_suite_cloud_manager_and_cloud_backup_module2.2.1.1.1
oracle oraclee-business_suite_information_discovery{"startIncluding":"12.2.3","endIncluding":"12.2.11"}
oracle oracleenterprise_manager_base_platform13.4.0.0
oracle oracleenterprise_manager_base_platform13.5.0.0
oracle oraclefinancial_services_revenue_management_and_billing_analytics2.7.0.0
oracle oraclefinancial_services_revenue_management_and_billing_analytics2.7.0.1
oracle oraclefinancial_services_revenue_management_and_billing_analytics2.8.0.0
oracle oraclehealthcare_foundation8.1.0
oracle oraclehyperion_data_relationship_management{"endExcluding":"11.2.8.0"}11.2.8.0
oracle oraclehyperion_infrastructure_technology{"endExcluding":"11.2.8.0"}11.2.8.0
oracle oracleidentity_management_suite12.2.1.3.0
oracle oracleidentity_management_suite12.2.1.4.0
oracle oracleidentity_manager_connector11.1.1.5.0
oracle oraclejdeveloper12.2.1.3.0
oracle oraclemiddleware_common_libraries_and_tools12.2.1.4.0
oracle oraclemysql_enterprise_monitor{"endIncluding":"8.0.29"}
oracle oracleretail_extract_transform_and_load13.2.5
oracle oracletuxedo12.2.2.0.0
oracle oracleweblogic_server12.2.1.3.0
oracle oracleweblogic_server12.2.1.4.0
oracle oracleweblogic_server14.1.1.0.0

References

CWEs

CWE-89

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.