Deserialization of Untrusted Data in Apache Log4j - CVE-2022-23302
Published: January 18, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data in JMSSink. A remote attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests and execute arbitrary code on the target system.
Note, a non-default configuration with support for JMSSink is required to exploit this vulnerability.
Affected software
Crypto Hardware Initialization and Maintenance (CHIM)
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
CentOS
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
openEuler
IBM Sterling Order Management
Cúram Social Program Management (SPM)
Datacap
DevOps
IBM Telco Network Cloud Manager - Performance (TNCP)
IBM Cloud Pak for Data System
Jazz for Service Management
IBM Operations Analytics Predictive Insights
Spectrum Discover
Enterprise Project Connection
IBM Sterling Connect:Direct Web Services
JBoss A-MQ
Splunk AppDynamics Database Agent
Log Analysis
Netcool Operations Insight
Unified Mediation Bus
IBM Security Access Manager for Enterprise Single-Sign On
Security Director Insights
Red Hat Software Collections
log4j (Red Hat package)
eap7-jboss-server-migration (Red Hat package)
eap7-wildfly-elytron (Red Hat package)
eap7-undertow (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
ovirt-engine (Red Hat package)
rhvm-branding-rhv (Red Hat package)
eap7-hibernate (Red Hat package)
tomcat7 (Red Hat package)
eap7-wildfly (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
tomcat8 (Red Hat package)
liblog4j1.2-java (Ubuntu package)
eap7-wildfly-openssl-el7 (Red Hat package)
eap7-wildfly-openssl-el8 (Red Hat package)
parfait
parfait-examples
parfait-javadoc
pcp-parfait-agent
eap7-yasson (Red Hat package)
log4j-jboss-logmanager (Red Hat package)
eap7-log4j-jboss-logmanager (Red Hat package)
log4j-manual
log4j
log4j-eap6 (Red Hat package)
apache-log4j1.2 (Ubuntu package)
log4j12
log4j12-manual
log4j12-javadoc
log4j-javadoc
rh-maven36-log4j12 (Red Hat package)
log4j12-help
eap7-xom (Red Hat package)
eap7-wildfly-openssl (Red Hat package)
eap7-activemq-artemis (Red Hat package)
eap7-log4j (Red Hat package)
eap7-jboss-vfs (Red Hat package)
eap7-hal-console (Red Hat package)
snmp4j (Red Hat package)
eap7-ecj (Red Hat package)
eap7-jbossws-cxf (Red Hat package)
eap7-narayana (Red Hat package)
eap7-objectweb-asm (Red Hat package)
eap7-infinispan (Red Hat package)
rh-sso7-keycloak (Red Hat package)
AMQ Streams
Fuse
JBoss Enterprise Application Platform
IBM WebSphere Application Server
IBM WebSphere Application Server Liberty
IBM Db2 Web Query for i
Cloudera Data Platform Private Cloud Base for IBM
IBM Cloud Pak for Multicloud Management
IBM Content Navigator
JBoss Web Server
Red Hat Virtualization Manager
JBoss Data Virtualization
JBoss Data Grid
IBM Qradar SIEM
IBM Cognos Controller
Red Hat Single Sign-On
IBM Cloud Pak System
How to mitigate CVE-2022-23302
log4j (Red Hat package) - addressed in versions 1.2.17-17.el7_3, 1.2.17-18.el7_4
AMQ Streams - addressed in versions 1.6.7, 2.0.1
eap7-jboss-server-migration (Red Hat package) - addressed in versions 1.10.0-15.Final_redhat_00014.1.el7eap, 1.10.0-15.Final_redhat_00014.1.el8eap
eap7-wildfly-elytron (Red Hat package) - addressed in versions 1.15.11-1.Final_redhat_00002.1.el7eap, 1.15.11-1.Final_redhat_00002.1.el8eap
Spectrum Discover - update to 2.0.4.5
eap7-undertow (Red Hat package) - addressed in versions 2.2.16-1.Final_redhat_00001.1.el7eap, 2.2.16-1.Final_redhat_00001.1.el8eap
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008 LA2, 3.2.0 IF004
JBoss Web Server - update to 3.1.14
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.8.6-1.Final_redhat_00001.1.el7eap, 3.8.6-1.Final_redhat_00001.1.el8eap
ovirt-engine (Red Hat package) - update to 4.4.10.6-0.1.el8ev
rhvm-branding-rhv (Red Hat package) - update to 4.4.10-1.el8ev
eap7-hibernate (Red Hat package) - addressed in versions 5.3.25-1.Final_redhat_00002.1.el7eap, 5.3.25-1.Final_redhat_00002.1.el8eap
Fuse - addressed in versions 6.3.20, 7.10.1
JBoss A-MQ - update to 6.3.20
JBoss Data Virtualization - addressed in versions 6.4.8.SP1, 6.4.8 SP2
JBoss Enterprise Application Platform - update to 7.4.4
tomcat7 (Red Hat package) - update to 7.0.70-46.ep7.el7
JBoss Data Grid - update to 7.3.9
Red Hat Single Sign-On - addressed in versions 7.4.10, 7.5.1
eap7-wildfly (Red Hat package) - addressed in versions 7.4.4-3.GA_redhat_00011.1.el7eap, 7.4.4-3.GA_redhat_00011.1.el8eap
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF01
tomcat8 (Red Hat package) - update to 8.0.36-49.ep7.el7
Datacap - update to 9.1.10
IBM WebSphere Application Server Liberty - update to 22.0.0.1
Splunk AppDynamics Database Agent - update to 26.1.0
liblog4j1.2-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2.17-8+deb10u1ubuntu0.2, 1.2.17-9ubuntu0.2
eap7-wildfly-openssl-el7 (Red Hat package) - update to x86_64-2.2.0-2.Final_redhat_00002.1.el7eap
eap7-wildfly-openssl-el8 (Red Hat package) - update to x86_64-2.2.0-2.Final_redhat_00002.1.el8eap
parfait - update to 0.5.4-4
parfait-examples - update to 0.5.4-4
parfait-javadoc - update to 0.5.4-4
pcp-parfait-agent - update to 0.5.4-4
eap7-yasson (Red Hat package) - addressed in versions 1.0.10-1.redhat_00001.1.el7eap, 1.0.10-1.redhat_00001.1.el8eap
log4j-jboss-logmanager (Red Hat package) - addressed in versions 1.1.4-3.Final_redhat_00002.1.ep6.el6, 1.1.4-3.Final_redhat_00002.1.ep6.el7
eap7-log4j-jboss-logmanager (Red Hat package) - addressed in versions 1.2.2-1.Final_redhat_00002.1.el7eap, 1.2.2-1.Final_redhat_00002.1.el8eap
log4j-manual - addressed in versions 1.2.15-126.9.1, 1.2.17-5.9.1
log4j - addressed in versions 1.2.15-126.9.1, 1.2.17-5.9.1
log4j-eap6 (Red Hat package) - addressed in versions 1.2.17-3.redhat_00008.1.ep6.el6, 1.2.17-3.redhat_00008.1.ep6.el7
apache-log4j1.2 (Ubuntu package) - update to 1.2.17-4ubuntu3+esm2
log4j12 - update to 1.2.17-4.9.1
log4j12-manual - update to 1.2.17-4.9.1
log4j12-javadoc - update to 1.2.17-4.9.1
log4j - update to 1.2.17-16.14
log4j - update to 1.2.17-18
log4j-javadoc - update to 1.2.17-18
log4j-manual - update to 1.2.17-18
rh-maven36-log4j12 (Red Hat package) - update to 1.2.17-23.4.el7
log4j12-help - update to 1.2.17-25
log4j12 - update to 1.2.17-25
eap7-xom (Red Hat package) - addressed in versions 1.3.7-1.redhat_00001.1.el7eap, 1.3.7-1.redhat_00001.1.el8eap
Log Analysis - update to 1.3.7.2
Netcool Operations Insight - update to 1.6.7
eap7-wildfly-openssl (Red Hat package) - addressed in versions 2.2.0-3.Final_redhat_00002.1.el7eap, 2.2.0-3.Final_redhat_00002.1.el8eap
IBM Cloud Pak System - update to 2.3.3.4
eap7-activemq-artemis (Red Hat package) - addressed in versions 2.16.0-7.redhat_00034.1.el7eap, 2.16.0-7.redhat_00034.1.el8eap
eap7-log4j (Red Hat package) - addressed in versions 2.17.1-1.redhat_00001.1.el7eap, 2.17.1-1.redhat_00001.1.el8eap
eap7-jboss-vfs (Red Hat package) - addressed in versions 3.2.16-1.Final_redhat_00001.1.el7eap, 3.2.16-1.Final_redhat_00001.1.el8eap
eap7-hal-console (Red Hat package) - addressed in versions 3.3.9-1.Final_redhat_00001.1.el7eap, 3.3.9-1.Final_redhat_00001.1.el8eap
snmp4j (Red Hat package) - update to 3.6.4-0.1.el8ev
eap7-ecj (Red Hat package) - addressed in versions 3.26.0-1.redhat_00002.1.el7eap, 3.26.0-1.redhat_00002.1.el8eap
Unified Mediation Bus - update to 4.4
eap7-jbossws-cxf (Red Hat package) - addressed in versions 5.4.4-1.Final_redhat_00001.1.el7eap, 5.4.4-1.Final_redhat_00001.1.el8eap
eap7-narayana (Red Hat package) - addressed in versions 5.11.4-1.Final_redhat_00001.1.el7eap, 5.11.4-1.Final_redhat_00001.1.el8eap
DevOps - update to 7.0.0.2
IBM Security Access Manager for Enterprise Single-Sign On - update to 8.2.2 Fix Pack 15
eap7-objectweb-asm (Red Hat package) - addressed in versions 9.1.0-1.redhat_00002.1.el7eap, 9.1.0-1.redhat_00002.1.el8eap
eap7-infinispan (Red Hat package) - addressed in versions 11.0.15-1.Final_redhat_00001.1.el7eap, 11.0.15-1.Final_redhat_00001.1.el8eap
rh-sso7-keycloak (Red Hat package) - addressed in versions 15.0.4-1.redhat_00003.1.el7sso, 15.0.4-1.redhat_00003.1.el8sso
Security Director Insights - update to 23.1R1
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Log4j
- Red Hat Enterprise Linux 8.4 update for the parfait:0.5 module
- Red Hat Enterprise Linux 8 update for the parfait:0.5 module
- Red Hat Enterprise Linux 8.2 update for the parfait:0.5 module
- Red Hat Enterprise Linux 8.1 update for the parfait:0.5 module
- Multiple vulnerabilities in IBM Db2 Web Query for i
- Multiple vulnerabilities in Red Hat Data Grid
- Red Hat Software Collections update for rh-maven36-log4j12
- Red Hat JBoss Enterprise Application Platform 7.4 update for Apache Log4j
- Red Hat JBoss Enterprise Application Platform 6.4 update for Apache Log4j
- CentOS 7 update for log4j
- Red Hat Single Sign-On update for Apache Log4j
- Multiple vulnerabilities in Red Hat Single Sign-On 7.5 for Red Hat Enterprise Linux 8
- Multiple vulnerabilities in Red Hat Single Sign-On for Red Hat Enterprise Linux 7
- Multiple vulnerabilities in Red Hat Single Sign-On
- Red Hat Enterprise Linux Server 7 update for log4j
- Multiple vulnerabilities in Red Hat AMQ Streams 1.6
- Multiple vulnerabilities in Red Hat AMQ Streams 2.0
- Multiple vulnerabilities in Red Hat Virtualization Manager
- Multiple vulnerabilities in Red Hat JBoss Data Virtualization
- Multiple vulnerabilities in Red Hat JBoss Data Virtualization
- Multiple vulnerabilities in Red Hat JBoss Web Server 3.1
- Multiple vulnerabilities in Red Hat JBoss Fuse and A-MQ
- Remote code execution in IBM Connect:Direct Web Services (Apache Log4j component)
- Multiple vulnerabilities in IBM WebSphere Application Server
- Multiple vulnerabilities in Red Hat Fuse 7.10
- Remote code execution in IBM Cloud Pak for Data System 1.0
- Multiple vulnerabilities in Cloudera Data Platform Private Cloud Base for IBM
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- JBoss Enterprise Application Platform 7.4 for RHEL 8 update for log4j
- JBoss Enterprise Application Platform 7.4 for RHEL 7 update for log4j
- Multiple vulnerabilities in IBM Telco Network Cloud Manager - Performance
- Multiple vulnerabilities in IBM Cognos Controller
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM Spectrum Discover
- Remote code execution in IBM Sterling Order Management
- Remote code execution in IBM Operations Analytics Predictive Insights
- SUSE update for log4j
- SUSE update for log4j
- SUSE update for log4j12
- Ubuntu update for apache-log4j1.2
- Amazon Linux AMI update for log4j
- Multiple vulnerabilities in IBM Security Access Manager for Enterprise Single Sign-On
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Networks Security Director Insights
- Multiple vulnerabilities in HPE Unified Mediation Bus (UMB)
- Gentoo update for Apache Log4j
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- openEuler update for log4j12
- openEuler 22.03 LTS update for log4j12
- Multiple vulnerabilities in IBM DevOps Release
- Multiple vulnerabilities in SAP Enterprise Project Connection
- Anolis OS update for parfait:0.5 module
- Anolis OS update for log4j
- Ubuntu update for apache-log4j1.2
- Multiple vulnerabilities in IBM Jazz for Service Management
- Multiple vulnerabilities in Crypto Hardware Initialization and Maintenance (CHIM) as shipped with IBM Common Cryptographic Architecture (CCA)
- Multiple vulnerabilities in IBM Cúram Social Program Management (SPM)
- Multiple vulnerabilities in IBM Datacap
- Splunk AppDynamics Database Agent update for third-party components
- Multiple vulnerabilities in IBM Content Navigator