PT-2019-5314 · Apache+6 · Log4J+6

Korean_Buljumuk

·

Published

2017-08-07

·

Updated

2026-05-19

·

CVE-2019-17571

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Log4j versions 1.2 up to 1.2.17
Description The issue is related to the deserialization of untrusted data in the SocketServer class of Log4j 1.2, which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget. This can occur when listening to untrusted network traffic for log data. According to the director of CISA, Log4j vulnerabilities will be used for invasions in the future. It is mentioned that 32 applications from the German software manufacturer SAP used the vulnerable Apache Log4j library, and SAP was only able to fix some of them by releasing the first set of security updates in 2022.
Recommendations To resolve the issue, migrate to org.apache.logging.log4j:log4j-core. As a temporary workaround, consider disabling the SocketServer class until a patch is available. Restrict access to the vulnerable Log4j library to minimize the risk of exploitation. Avoid using the vulnerable SocketServer class in the affected Log4j versions until the issue is resolved.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

ALSA-2022_0290
BDU:2020-02355
CESA-2017_2423
CVE-2019-17571
DLA-2065-1
DSA-4686-1
GHSA-2QRG-X229-3V8Q
MGASA-2023-0141
OPENSUSE-SU-2020:0051-1
OPENSUSE-SU-2020_0051-1
OPENSUSE-SU-2024:11025-1
OPENSUSE-SU-2024:11026-1
RHSA-2017:1801
RHSA-2017:2423
RHSA-2017:2638
RHSA-2017:2811
RHSA-2017:3399
RHSA-2017_2423
RHSA-2022:5053
RHSA-2022_5053
ROSA-SA-2024-2519
SUSE-SU-2020:0053-1
SUSE-SU-2020:0054-1
SUSE-SU-2020:14267-1
SUSE-SU-2020_0053-1
SUSE-SU-2020_0054-1
SUSE-SU-2020_14267-1
USN-4495-1
USN-5998-1

Affected Products

Centos
Linuxmint
Log4J
Oracle Weblogic Server
Red Hat
Suse
Ubuntu