Tracker / CVE-2019-17571
CVE-2019-17571
Critical 9.8
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
Affected products and versions
| apache | bookkeeper · … → 4.14.3 |
|---|---|
| apache | log4j · … → 1.2.17 |
| canonical | ubuntu_linux |
| debian | debian_linux |
| netapp | oncommand_system_manager · 3.0 → 3.1.3 |
| netapp | oncommand_workflow_automation |
| opensuse | leap |
| oracle | application_testing_suite |
| oracle | communications_network_integrity · 7.3.2 → 7.3.6 |
| oracle | endeca_information_discovery_studio |
| oracle | financial_services_lending_and_leasing |
| oracle | financial_services_lending_and_leasing · 14.1.0 → 14.8.0 |
| oracle | mysql_enterprise_monitor · … → 8.0.29 |
| oracle | primavera_gateway · 16.2 → 16.2.11 |
| oracle | primavera_gateway · 17.12.0 → 17.12.7 |
| oracle | rapid_planning |
| oracle | retail_extract_transform_and_load |
| oracle | retail_service_backbone |
| oracle | weblogic_server |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.