CVE-2017-5645

Scores

EPSS

0.940high94.0%
0%20%40%60%80%100%

Percentile: 94.0%

CVSS

8.1high3.x
0246810

CVSS Score: 8.1/10

All CVSS Scores

CVSS 3.x
8.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhatubuntu

CWEs

CWE-502

Related Vulnerabilities

Exploits

Exploit ID: CVE-2017-5645

Source: github-poc

URL: https://github.com/pimps/CVE-2017-5645

Recommendations

Source: nvd

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications.
The References section of this erratum contains a download link (you must log in to download the update).

URL: https://access.redhat.com/errata/RHSA-2017:3400

Source: nvd

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications.
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

URL: https://access.redhat.com/errata/RHSA-2017:3399

Source: nvd

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

URL: https://access.redhat.com/errata/RHSA-2017:2423

Source: nvd

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

URL: https://access.redhat.com/errata/RHSA-2017:1417

Vulnerable Software (393)

Type: Configuration

Product: apache-cxf

Operating System: rhel

Trait:
{  "fixed": "2.7.18-7.SP6_redhat_1.1.ep6.el5"}

Source: redhat

Type: Configuration

Product: apache-cxf

Operating System: rhel

Trait:
{  "fixed": "2.7.18-7.SP6_redhat_1.1.ep6.el6"}

Source: redhat

Type: Configuration

Product: apache-cxf

Operating System: rhel

Trait:
{  "fixed": "2.7.18-7.SP6_redhat_1.1.ep6.el7"}

Source: redhat

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu bionic 18.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu disco 19.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu eoan 19.10

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu focal 20.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu hirsute 21.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu impish 21.10

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu jammy 22.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu kinetic 22.10

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu lunar 23.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu mantic 23.10

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu noble 24.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu oracular 24.10

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu plucky 25.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu questing 25.10

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu xenial 16.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu yakkety 16.10

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: apache-log4j2

Operating System: ubuntu zesty 17.04

Trait:
{  "unfixed": true}

Source: ubuntu