← All CVEs

CVE-2017-5645

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

9.8
CVSS
89.8%
EPSS (exploit prob.)
100th
EPSS percentile
2017-04-17
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
apachelog4j>= 2.0, < 2.8.2
netapponcommand_api_servicesall versions
netapponcommand_insightall versions
netapponcommand_workflow_automationall versions
netappservice_level_managerall versions
netappsnapcenterall versions
netappstorage_automation_storeall versions
redhatfuse1.0
redhatenterprise_linux6.0
redhatenterprise_linux6.7
redhatenterprise_linux7.0
redhatenterprise_linux7.3
redhatenterprise_linux7.4
redhatenterprise_linux7.5
redhatenterprise_linux7.6
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_aus7.4
redhatenterprise_linux_server_aus7.6
redhatenterprise_linux_server_eus7.4
redhatenterprise_linux_server_eus7.5
redhatenterprise_linux_server_eus7.6
redhatenterprise_linux_server_tus7.4
redhatenterprise_linux_server_tus7.6
redhatenterprise_linux_workstation7.0
oracleapi_gateway11.1.2.4.0
oracleapplication_testing_suite13.3.0.1
oracleautovue_vuelink_integration21.0.0
oracleautovue_vuelink_integration21.0.1
oraclebanking_platform2.6.0
oraclebanking_platform2.6.1
oraclebanking_platform2.6.2
oraclebi_publisher11.1.1.7.0
oraclebi_publisher11.1.1.9.0
oraclebi_publisher12.2.1.3.0
oraclebi_publisher12.2.1.4.0
oraclecommunications_converged_application_server_-_service_controller6.1
oraclecommunications_instant_messaging_server10.0.1.3.0
oraclecommunications_interactive_session_recorder>= 6.0, <= 6.2
oraclecommunications_messaging_server< 8.0.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-5645