CVE-2017-5645

9.8 CRITICAL
Published: April 17, 2017 Modified: May 13, 2026
View on NVD

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/12/19/2
Source: security@apache.org
Mailing List Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
Source: security@apache.org
Patch Third Party Advisory
http://www.securityfocus.com/bid/97702
Source: security@apache.org
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040200
Source: security@apache.org
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1041294
Source: security@apache.org
Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:1417
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1801
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1802
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2423
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2633
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2635
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2636
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2637
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2638
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2808
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2809
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2810
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2811
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2888
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2889
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3244
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3399
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3400
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1545
Source: security@apache.org
Third Party Advisory
https://issues.apache.org/jira/browse/LOG4J2-1863
Source: security@apache.org
Issue Tracking Vendor Advisory
https://security.netapp.com/advisory/ntap-20180726-0002/
Source: security@apache.org
Third Party Advisory
https://security.netapp.com/advisory/ntap-20181107-0002/
Source: security@apache.org
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Source: security@apache.org
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
Source: security@apache.org
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html
Source: security@apache.org
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html
Source: security@apache.org
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Source: security@apache.org
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Source: security@apache.org
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Source: security@apache.org
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Source: security@apache.org
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
Source: security@apache.org
Patch Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Source: security@apache.org
Patch Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Source: security@apache.org
Patch Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Source: security@apache.org
Patch Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/12/19/2
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
http://www.securityfocus.com/bid/97702
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040200
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1041294
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:1417
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1801
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1802
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2423
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2633
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2635
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2636
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2637
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2638
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2808
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2809
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2810
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2811
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2888
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2889
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3244
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3399
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3400
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1545
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://issues.apache.org/jira/browse/LOG4J2-1863
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Vendor Advisory
https://security.netapp.com/advisory/ntap-20180726-0002/
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://security.netapp.com/advisory/ntap-20181107-0002/
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory

164 reference(s) from NVD

Quick Stats

CVSS v3 Score
9.8 / 10.0
EPSS (Exploit Probability)
89.0%
100th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

netapp oracle apache redhat