imPC@ndo EN

Tracker / CVE-2019-17571

CVE-2019-17571

Critica 9.8

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

Prodotti e versioni affette

apache bookkeeper · … → 4.14.3
apache log4j · … → 1.2.17
canonical ubuntu_linux
debian debian_linux
netapp oncommand_system_manager · 3.0 → 3.1.3
netapp oncommand_workflow_automation
opensuse leap
oracle application_testing_suite
oracle communications_network_integrity · 7.3.2 → 7.3.6
oracle endeca_information_discovery_studio
oracle financial_services_lending_and_leasing
oracle financial_services_lending_and_leasing · 14.1.0 → 14.8.0
oracle mysql_enterprise_monitor · … → 8.0.29
oracle primavera_gateway · 16.2 → 16.2.11
oracle primavera_gateway · 17.12.0 → 17.12.7
oracle rapid_planning
oracle retail_extract_transform_and_load
oracle retail_service_backbone
oracle weblogic_server

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti