Deserialization of untrusted data in Apache Log4j - CVE-2017-5645
Published: April 24, 2018
Vulnerability identifier: #VU12127
CSH Severity: High
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5645
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists receiving serialized log events from another application when using the TCP socket server or UDP socket server. A remote attacker can submit a specially crafted binary payload, when deserialized, and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists receiving serialized log events from another application when using the TCP socket server or UDP socket server. A remote attacker can submit a specially crafted binary payload, when deserialized, and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Apache Log4j
Tape Library ACSLS
Amazon Linux AMI
Fedora
Oracle Utilities Advanced Spatial and Operational Analytics
Instantis EnterpriseTrack
Oracle Endeca Information Discovery Studio
Identity Manager Connector
Oracle SOA Suite
JD Edwards EnterpriseOne Tools
Oracle GoldenGate Application Adapters
Oracle Communications Service Broker
Oracle Communications Online Mediation Controller
Oracle Insurance Rules Palette
Oracle FLEXCUBE Investor Servicing
Oracle Financial Services Lending and Leasing
Oracle Application Testing Suite
Oracle Communications Interactive Session Recorder
Oracle Communications Instant Messaging Server
Oracle Communications Converged Application Server - Service Controller
Oracle Communications Network Integrity
Oracle Financial Services Regulatory Reporting with AgileREPORTER
Oracle In-Memory Performance-Driven Planning
Oracle Communications WebRTC Session Controller
IBM Cloud Application Performance Management (APM)
JBoss Enterprise Application Platform
Oracle WebLogic Server
Primavera Gateway
Fuse
Oracle Insurance Calculation Engine
Oracle TimesTen In-Memory Database
Oracle Retail Advanced Inventory Planning
rh-java-common-log4j (Red Hat package)
log4j12
log4j
eap7-jboss-ec2-eap (Red Hat package)
JBoss Data Grid
Tape Library ACSLS
Amazon Linux AMI
Fedora
Oracle Utilities Advanced Spatial and Operational Analytics
Instantis EnterpriseTrack
Oracle Endeca Information Discovery Studio
Identity Manager Connector
Oracle SOA Suite
JD Edwards EnterpriseOne Tools
Oracle GoldenGate Application Adapters
Oracle Communications Service Broker
Oracle Communications Online Mediation Controller
Oracle Insurance Rules Palette
Oracle FLEXCUBE Investor Servicing
Oracle Financial Services Lending and Leasing
Oracle Application Testing Suite
Oracle Communications Interactive Session Recorder
Oracle Communications Instant Messaging Server
Oracle Communications Converged Application Server - Service Controller
Oracle Communications Network Integrity
Oracle Financial Services Regulatory Reporting with AgileREPORTER
Oracle In-Memory Performance-Driven Planning
Oracle Communications WebRTC Session Controller
IBM Cloud Application Performance Management (APM)
JBoss Enterprise Application Platform
Oracle WebLogic Server
Primavera Gateway
Fuse
Oracle Insurance Calculation Engine
Oracle TimesTen In-Memory Database
Oracle Retail Advanced Inventory Planning
rh-java-common-log4j (Red Hat package)
log4j12
log4j
eap7-jboss-ec2-eap (Red Hat package)
JBoss Data Grid
How to mitigate CVE-2017-5645
Update to version 2.8.2.
Oracle TimesTen In-Memory Database - update to 11.2.2.8.49
rh-java-common-log4j (Red Hat package) - addressed in versions 1.2.17-15.15.el6, 1.2.17-15.15.el7
log4j12 - addressed in versions 1.2.17-19.fc24, 1.2.17-19.fc25, 1.2.17-19.fc26
log4j - addressed in versions 2.5-3.fc24, 2.5-5.fc25, 2.7-4.fc26
eap7-jboss-ec2-eap (Red Hat package) - addressed in versions 7.0.8-1.GA_redhat_1.ep7.el6, 7.0.8-1.GA_redhat_1.ep7.el7
JBoss Data Grid - update to 7.1.1
Oracle Communications WebRTC Session Controller - update to 7.2
Fuse - update to 7.3.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
rh-java-common-log4j (Red Hat package) - addressed in versions 1.2.17-15.15.el6, 1.2.17-15.15.el7
log4j12 - addressed in versions 1.2.17-19.fc24, 1.2.17-19.fc25, 1.2.17-19.fc26
log4j - addressed in versions 2.5-3.fc24, 2.5-5.fc25, 2.7-4.fc26
eap7-jboss-ec2-eap (Red Hat package) - addressed in versions 7.0.8-1.GA_redhat_1.ep7.el6, 7.0.8-1.GA_redhat_1.ep7.el7
JBoss Data Grid - update to 7.1.1
Oracle Communications WebRTC Session Controller - update to 7.2
Fuse - update to 7.3.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
External References
Related Security Bulletins
- Remote code execution in Apache Log4
- Multiple vulnerabilities in Oracle Sun Systems Products Suite
- Red Hat update for jboss-ec2-eap
- Multiple vulnerabilities in Oracle Communications Instant Messaging Server
- Multiple vulnerabilities in Instantis EnterpriseTrack
- Multiple vulnerabilities in Oracle Retail Advanced Inventory Planning
- Deserialization of untrusted data in Oracle In-Memory Performance-Driven Planning
- Deserialization of untrusted data in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in Oracle Communications Network Integrity
- Multiple vulnerabilities in Primavera Gateway
- Multiple vulnerabilities in Oracle Application Testing Suite
- Multiple vulnerabilities in Oracle Financial Services Lending and Leasing
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in Oracle Endeca Information Discovery Studio
- Multiple vulnerabilities in Oracle Insurance Rules Palette
- Multiple vulnerabilities in Oracle Insurance Calculation Engine
- Multiple vulnerabilities in Oracle TimesTen In-Memory Database
- Multiple vulnerabilities in Oracle Financial Services Regulatory Reporting with AgileREPORTER
- Deserialization of untrusted data in Identity Manager Connector
- Amazon Linux AMI update for log4j
- Multiple vulnerabilities in IBM Application Performance Management products
- Fedora 26 update for log4j
- Fedora 25 update for log4j
- Fedora 24 update for log4j
- Fedora 26 update for log4j12
- Fedora 25 update for log4j12
- Fedora 24 update for log4j12
- Red Hat Software Collections update for rh-java-common-log4j
- Red Hat JBoss Enterprise Application Platform 7 update for eap7-jboss-ec2-eap
- Multiple vulnerabilities in JBoss Data Grid 7.1
- Multiple vulnerabilities in Fuse 7.3
- Multiple vulnerabilities in Oracle Communications Interactive Session Recorder
- Deserialization of untrusted data in Oracle SOA Suite
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in Oracle Utilities Advanced Spatial and Operational Analytics
- Multiple vulnerabilities in Tape Library ACSLS
- Deserialization of untrusted data in Oracle GoldenGate Application Adapters
- Deserialization of untrusted data in Oracle SOA Suite
- Multiple vulnerabilities in Oracle FLEXCUBE Investor Servicing
- Multiple vulnerabilities in Oracle Communications WebRTC Session Controller
- Deserialization of untrusted data in Oracle Communications Online Mediation Controller
- Deserialization of untrusted data in Oracle Communications Service Broker
- Deserialization of untrusted data in Oracle Communications Converged Application Server - Service Controller