CVE-2022-23307
high · 8.8CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
8.8
CVSS
54.4%
EPSS (exploit prob.)
99th
EPSS percentile
2022-01-18
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | chainsaw | < 2.1.0 |
| apache | log4j | >= 1.2, < 2.0 |
| qos | reload4j | < 1.2.18.1 |
| oracle | advanced_supply_chain_planning | 12.1 |
| oracle | advanced_supply_chain_planning | 12.2 |
| oracle | business_intelligence | 5.9.0.0.0 |
| oracle | business_intelligence | 12.2.1.3.0 |
| oracle | business_intelligence | 12.2.1.4.0 |
| oracle | business_process_management_suite | 12.2.1.3.0 |
| oracle | business_process_management_suite | 12.2.1.4.0 |
| oracle | communications_eagle_ftp_table_base_retrieval | 4.5 |
| oracle | communications_instant_messaging_server | 10.0.1.5.0 |
| oracle | communications_messaging_server | 8.1 |
| oracle | communications_network_integrity | 7.3.6 |
| oracle | communications_offline_mediation_controller | < 12.0.0.4.4 |
| oracle | communications_offline_mediation_controller | 12.0.0.5.0 |
| oracle | communications_unified_inventory_management | 7.4.1 |
| oracle | communications_unified_inventory_management | 7.4.2 |
| oracle | e-business_suite_cloud_manager_and_cloud_backup_module | < 2.2.1.1.1 |
| oracle | e-business_suite_cloud_manager_and_cloud_backup_module | 2.2.1.1.1 |
| oracle | enterprise_manager_base_platform | 13.4.0.0 |
| oracle | enterprise_manager_base_platform | 13.5.0.0 |
| oracle | financial_services_revenue_management_and_billing_analytics | 2.7.0.0 |
| oracle | financial_services_revenue_management_and_billing_analytics | 2.7.0.1 |
| oracle | financial_services_revenue_management_and_billing_analytics | 2.8.0.0 |
| oracle | healthcare_foundation | 8.1.0 |
| oracle | hyperion_data_relationship_management | < 11.2.8.0 |
| oracle | hyperion_infrastructure_technology | < 11.2.8.0 |
| oracle | identity_management_suite | 12.2.1.3.0 |
| oracle | identity_management_suite | 12.2.1.4.0 |
| oracle | identity_manager_connector | 11.1.1.5.0 |
| oracle | jdeveloper | 12.2.1.3.0 |
| oracle | middleware_common_libraries_and_tools | 12.2.1.4.0 |
| oracle | mysql_enterprise_monitor | <= 8.0.29 |
| oracle | retail_extract_transform_and_load | 13.2.5 |
| oracle | tuxedo | 12.2.2.0.0 |
| oracle | weblogic_server | 12.2.1.3.0 |
| oracle | weblogic_server | 12.2.1.4.0 |
| oracle | weblogic_server | 14.1.1.0.0 |
Check a specific version with /api/v1/cve/match.
References
- https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh
- https://logging.apache.org/log4j/1.2/index.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh
- https://logging.apache.org/log4j/1.2/index.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-23307