In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Log4j
Subscribe
|
|
Netapp
Subscribe
|
|
|
Oracle
Subscribe
|
Api Gateway
Subscribe
Application Testing Suite
Subscribe
Autovue Vuelink Integration
Subscribe
Banking Platform
Subscribe
Bi Publisher
Subscribe
Communications Converged Application Server - Service Controller
Subscribe
Communications Instant Messaging Server
Subscribe
Communications Interactive Session Recorder
Subscribe
Communications Messaging Server
Subscribe
Communications Network Integrity
Subscribe
Communications Online Mediation Controller
Subscribe
Communications Pricing Design Center
Subscribe
Communications Service Broker
Subscribe
Communications Webrtc Session Controller
Subscribe
Configuration Manager
Subscribe
Endeca Information Discovery Studio
Subscribe
Enterprise Data Quality
Subscribe
Enterprise Manager Base Platform
Subscribe
Enterprise Manager For Fusion Middleware
Subscribe
Enterprise Manager For Mysql Database
Subscribe
Enterprise Manager For Oracle Database
Subscribe
Enterprise Manager For Peoplesoft
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Financial Services Behavior Detection Platform
Subscribe
Financial Services Hedge Management And Ifrs Valuations
Subscribe
Financial Services Lending And Leasing
Subscribe
Financial Services Loan Loss Forecasting And Provisioning
Subscribe
Financial Services Profitability Management
Subscribe
Financial Services Regulatory Reporting With Agilereporter
Subscribe
Flexcube Investor Servicing
Subscribe
Fusion Middleware Mapviewer
Subscribe
Goldengate
Subscribe
Goldengate Application Adapters
Subscribe
Identity Analytics
Subscribe
Identity Management Suite
Subscribe
Identity Manager Connector
Subscribe
In-memory Performance-driven Planning
Subscribe
Instantis Enterprisetrack
Subscribe
Insurance Calculation Engine
Subscribe
Insurance Policy Administration
Subscribe
Insurance Rules Palette
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Jdeveloper
Subscribe
Mysql Enterprise Monitor
Subscribe
Peoplesoft Enterprise Fin Install
Subscribe
Policy Automation
Subscribe
Policy Automation Connector For Siebel
Subscribe
Policy Automation For Mobile Devices
Subscribe
Primavera Gateway
Subscribe
Rapid Planning
Subscribe
Retail Advanced Inventory Planning
Subscribe
Retail Clearance Optimization Engine
Subscribe
Retail Extract Transform And Load
Subscribe
Retail Integration Bus
Subscribe
Retail Open Commerce Platform
Subscribe
Retail Predictive Application Server
Subscribe
Retail Service Backbone
Subscribe
Siebel Ui Framework
Subscribe
Soa Suite
Subscribe
Tape Library Acsls
Subscribe
Timesten In-memory Database
Subscribe
Utilities Advanced Spatial And Operational Analytics
Subscribe
Utilities Work And Asset Management
Subscribe
Weblogic Server
Subscribe
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Eus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Fuse
Subscribe
Jboss Bpms
Subscribe
Jboss Data Grid
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Enterprise Web Server
Subscribe
Jboss Fuse
Subscribe
Rhel Software Collections
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fxph-q3j8-mv87 | Deserialization of Untrusted Data in Log4j |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T15:11:47.391Z
Reserved: 2017-01-29T00:00:00.000Z
Link: CVE-2017-5645
No data.
Status : Deferred
Published: 2017-04-17T21:59:00.373
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-5645
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA