Deserialization of untrusted data in Apache Log4j - CVE-2017-5645

 

Deserialization of untrusted data in Apache Log4j - CVE-2017-5645

Published: April 24, 2018


Vulnerability identifier: #VU12127
CSH Severity: High
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5645
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists receiving serialized log events from another application when using the TCP socket server or UDP socket server. A remote attacker can submit a specially crafted binary payload, when deserialized, and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Apache Log4j
Tape Library ACSLS
Amazon Linux AMI
Fedora
Oracle Utilities Advanced Spatial and Operational Analytics
Instantis EnterpriseTrack
Oracle Endeca Information Discovery Studio
Identity Manager Connector
Oracle SOA Suite
JD Edwards EnterpriseOne Tools
Oracle GoldenGate Application Adapters
Oracle Communications Service Broker
Oracle Communications Online Mediation Controller
Oracle Insurance Rules Palette
Oracle FLEXCUBE Investor Servicing
Oracle Financial Services Lending and Leasing
Oracle Application Testing Suite
Oracle Communications Interactive Session Recorder
Oracle Communications Instant Messaging Server
Oracle Communications Converged Application Server - Service Controller
Oracle Communications Network Integrity
Oracle Financial Services Regulatory Reporting with AgileREPORTER
Oracle In-Memory Performance-Driven Planning
Oracle Communications WebRTC Session Controller
IBM Cloud Application Performance Management (APM)
JBoss Enterprise Application Platform
Oracle WebLogic Server
Primavera Gateway
Fuse
Oracle Insurance Calculation Engine
Oracle TimesTen In-Memory Database
Oracle Retail Advanced Inventory Planning
rh-java-common-log4j (Red Hat package)
log4j12
log4j
eap7-jboss-ec2-eap (Red Hat package)
JBoss Data Grid

How to mitigate CVE-2017-5645

Update to version 2.8.2.

Oracle TimesTen In-Memory Database - update to 11.2.2.8.49
rh-java-common-log4j (Red Hat package) - addressed in versions 1.2.17-15.15.el6, 1.2.17-15.15.el7
log4j12 - addressed in versions 1.2.17-19.fc24, 1.2.17-19.fc25, 1.2.17-19.fc26
log4j - addressed in versions 2.5-3.fc24, 2.5-5.fc25, 2.7-4.fc26
eap7-jboss-ec2-eap (Red Hat package) - addressed in versions 7.0.8-1.GA_redhat_1.ep7.el6, 7.0.8-1.GA_redhat_1.ep7.el7
JBoss Data Grid - update to 7.1.1
Oracle Communications WebRTC Session Controller - update to 7.2
Fuse - update to 7.3.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14

External References

Related Security Bulletins