Deserialization of Untrusted Data in Apache Log4j - CVE-2019-17571

 

Deserialization of Untrusted Data in Apache Log4j - CVE-2019-17571

Published: May 18, 2020 / Updated: March 10, 2026


Vulnerability identifier: #VU27960
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17571
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data within the SocketServer class in Log4j. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system,  if these is a deserialization gadget listening to untrusted network traffic for log data.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Apache Log4j
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Anolis OS
Opensuse
Ubuntu
IBM PureData System for Operational Analytics
IBM Integration Bus
Splunk AppDynamics Database Agent
Log Analysis
Netcool Operations Insight
Unified Mediation Bus
IBM Security Access Manager for Enterprise Single-Sign On
Security Director Insights
log4j (Red Hat package)
apache-log4j1.2 (Debian package)
liblog4j1.2-java (Ubuntu package)
log4j-manual
log4j-javadoc
log4j
IBM Cloud Pak for Multicloud Management
IBM Tivoli Network Manager (ITNM)
IBM Content Navigator
Communications Unified Assurance
JBoss Data Virtualization
IBM Qradar SIEM
Oracle WebLogic Server
IBM App Connect Enterprise
SAP Quotation Management Insurance (FS-QUO)
Dell EMC Storage Monitoring and Reporting (SMR)
DevOps
IBM Sterling Order Management

How to mitigate CVE-2019-17571

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

log4j (Red Hat package) - update to 1.2.14-6.7.el6_10
apache-log4j1.2 (Debian package) - addressed in versions 1.2.17-7+deb9u1, 1.2.17-8+deb10u1
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008 LA2, 3.2.0 IF004
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.15
JBoss Data Virtualization - addressed in versions 6.4.8.SP1, 6.4.8 SP2
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 7, 7.5.0 Update Package 3 Interim Fix 02, 7.5.0 Update Pack 7 IF01
Splunk AppDynamics Database Agent - update to 26.1.0
liblog4j1.2-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2.17-8+deb10u1ubuntu0.2, 1.2.17-8+deb10u1build0.18.04.1, 1.2.17-9ubuntu0.2
log4j-manual - update to 1.2.17-18
log4j-javadoc - update to 1.2.17-18
log4j - update to 1.2.17-18
Log Analysis - update to 1.3.7.2
Netcool Operations Insight - update to 1.6.7
Unified Mediation Bus - update to 4.4
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
DevOps - update to 7.0.0.2
IBM Security Access Manager for Enterprise Single-Sign On - update to 8.2.2 Fix Pack 15
IBM Sterling Order Management - update to 10.0.2403.1
Security Director Insights - update to 23.1R1

External References

Related Security Bulletins