Tracker / CVE-2019-17571
CVE-2019-17571
Critica 9.8
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
Prodotti e versioni affette
| apache | bookkeeper · … → 4.14.3 |
|---|---|
| apache | log4j · … → 1.2.17 |
| canonical | ubuntu_linux |
| debian | debian_linux |
| netapp | oncommand_system_manager · 3.0 → 3.1.3 |
| netapp | oncommand_workflow_automation |
| opensuse | leap |
| oracle | application_testing_suite |
| oracle | communications_network_integrity · 7.3.2 → 7.3.6 |
| oracle | endeca_information_discovery_studio |
| oracle | financial_services_lending_and_leasing |
| oracle | financial_services_lending_and_leasing · 14.1.0 → 14.8.0 |
| oracle | mysql_enterprise_monitor · … → 8.0.29 |
| oracle | primavera_gateway · 16.2 → 16.2.11 |
| oracle | primavera_gateway · 17.12.0 → 17.12.7 |
| oracle | rapid_planning |
| oracle | retail_extract_transform_and_load |
| oracle | retail_service_backbone |
| oracle | weblogic_server |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.