← All CVEs

CVE-2019-17571

critical · 9.8

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

9.8
CVSS
69.1%
EPSS (exploit prob.)
99th
EPSS percentile
2019-12-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
apachelog4j<= 1.2.17
debiandebian_linux8.0
debiandebian_linux9.0
debiandebian_linux10.0
canonicalubuntu_linux18.04
opensuseleap15.1
netapponcommand_system_manager>= 3.0, <= 3.1.3
netapponcommand_workflow_automationall versions
oracleapplication_testing_suite13.3.0.1
oraclecommunications_network_integrity>= 7.3.2, <= 7.3.6
oracleendeca_information_discovery_studio3.2.0
oraclefinancial_services_lending_and_leasing>= 14.1.0, <= 14.8.0
oraclefinancial_services_lending_and_leasing12.5.0
oraclemysql_enterprise_monitor<= 8.0.29
oracleprimavera_gateway>= 16.2, <= 16.2.11
oracleprimavera_gateway>= 17.12.0, <= 17.12.7
oraclerapid_planning12.1
oraclerapid_planning12.2
oracleretail_extract_transform_and_load19.0
oracleretail_service_backbone14.1
oracleretail_service_backbone15.0
oracleretail_service_backbone16.0
oracleweblogic_server10.3.6.0.0
oracleweblogic_server12.1.3.0.0
oracleweblogic_server12.2.1.3.0
oracleweblogic_server12.2.1.4.0
oracleweblogic_server14.1.1.0.0
apachebookkeeper< 4.14.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-17571