CVE-2017-5645

critical
Published 2017-04-17 · Modified 2024-03-14
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

Deserialization of Untrusted Data in Log4j

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2017-5645.html

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — https://issues.apache.org/jira/browse/LOG4J2-1863

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-5645

OS impact

OSVersionStatusFixed in
debian debiansidfixed2.7-2
debian debiantrixiefixed2.7-2
debian debianbookwormfixed2.7-2
debian debianbullseyefixed2.7-2
debian debianforkyfixed2.7-2
suse slesaffected
redhat rhel6.0affected
redhat rhel6.7affected
redhat rhel7.0affected
redhat rhel7.3affected
redhat rhel7.4affected
redhat rhel7.5affected
redhat rhel7.6affected

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.logging.log4j:log4j>=2.0,<2.8.22.8.2
java Mavenorg.apache.logging.log4j:log4j-core>=2.0,<2.8.22.8.2

Application impact

VendorProductVersionsFixed
apache apachelog4j{"startIncluding":"2.0","endExcluding":"2.8.2"}2.8.2
netapponcommand_api_services-
netapponcommand_insight-
netapponcommand_workflow_automation-
netappservice_level_manager-
netappsnapcenter-
netappstorage_automation_store-
redhatfuse1.0
oracleapi_gateway11.1.2.4.0
oracleapplication_testing_suite13.3.0.1
oracleautovue_vuelink_integration21.0.0
oracleautovue_vuelink_integration21.0.1
oraclebanking_platform2.6.0
oraclebanking_platform2.6.1
oraclebanking_platform2.6.2
oraclebi_publisher11.1.1.7.0
oraclebi_publisher11.1.1.9.0
oraclebi_publisher12.2.1.3.0
oraclebi_publisher12.2.1.4.0
oraclecommunications_converged_application_server_-_service_controller6.1
oraclecommunications_instant_messaging_server10.0.1.3.0
oraclecommunications_interactive_session_recorder{"startIncluding":"6.0","endIncluding":"6.2"}
oraclecommunications_messaging_server{"endExcluding":"8.0.2"}8.0.2
oraclecommunications_network_integrity{"startIncluding":"7.3.2","endIncluding":"7.3.6"}
oraclecommunications_online_mediation_controller6.1
oraclecommunications_pricing_design_center11.1
oraclecommunications_pricing_design_center12.0
oraclecommunications_service_broker6.0
oraclecommunications_webrtc_session_controller{"endExcluding":"7.2"}7.2
oracleconfiguration_manager12.1.2.0.2
oracleconfiguration_manager12.1.2.0.5
oracleendeca_information_discovery_studio3.2.0
oracleenterprise_data_quality12.2.1.3.0
oracleenterprise_manager_base_platform12.1.0.5
oracleenterprise_manager_base_platform13.2.0.0
oracleenterprise_manager_for_fusion_middleware12.1.0.5
oracleenterprise_manager_for_fusion_middleware13.2.0.0
oracleenterprise_manager_for_mysql_database{"endIncluding":"13.2.2.0.0"}
oracleenterprise_manager_for_oracle_database12.1.0.8
oracleenterprise_manager_for_oracle_database13.2.2
oracleenterprise_manager_for_peoplesoft13.1.1.1
oracleenterprise_manager_for_peoplesoft13.2.1.1
oracleretail_extract_transform_and_load13.2
oraclefinancial_services_analytical_applications_infrastructure{"startIncluding":"7.3.3.0.0","endIncluding":"7.3.3.0.2"}
oraclefinancial_services_behavior_detection_platform{"startIncluding":"8.0.0.0.0","endIncluding":"8.0.4.0.0"}
oraclefinancial_services_behavior_detection_platform6.1.1
oraclefinancial_services_hedge_management_and_ifrs_valuations8.0.4
oraclefinancial_services_hedge_management_and_ifrs_valuations8.0.5
oraclefinancial_services_lending_and_leasing{"startIncluding":"14.1.0","endIncluding":"14.8.0"}
oraclefinancial_services_lending_and_leasing12.5.0
oraclefinancial_services_loan_loss_forecasting_and_provisioning8.0.4
oraclefinancial_services_loan_loss_forecasting_and_provisioning8.0.5
oraclefinancial_services_profitability_management{"startIncluding":"8.0.0.0.0","endIncluding":"8.0.7.0.0"}
oraclefinancial_services_profitability_management6.1.1
oraclefinancial_services_regulatory_reporting_with_agilereporter8.0.9.2.0
oracleflexcube_investor_servicing12.0.4
oracleflexcube_investor_servicing12.1.0
oracleflexcube_investor_servicing12.3.0
oracleflexcube_investor_servicing12.4.0
oracleflexcube_investor_servicing14.0.0
oraclefusion_middleware_mapviewer12.2.1.2
oraclefusion_middleware_mapviewer12.2.1.3
oraclegoldengate12.3.2.1.1
oraclegoldengate_application_adapters12.3.2.1.1
oracleidentity_analytics11.1.1.5.8
oracleidentity_management_suite11.1.2.3.0
oracleidentity_management_suite12.2.1.3.0
oracleidentity_manager_connector9.0
oraclein-memory_performance-driven_planning12.1
oraclein-memory_performance-driven_planning12.2
oracleinstantis_enterprisetrack{"startIncluding":"17.1","endIncluding":"17.3"}
oracleinsurance_calculation_engine10.1.1
oracleinsurance_calculation_engine10.2.1
oracleinsurance_policy_administration10.0
oracleinsurance_policy_administration10.1
oracleinsurance_policy_administration10.2
oracleinsurance_policy_administration11.0
oracleinsurance_rules_palette10.0
oracleinsurance_rules_palette10.1
oracleinsurance_rules_palette10.2
oracleinsurance_rules_palette11.0
oracleinsurance_rules_palette11.1
oraclejd_edwards_enterpriseone_tools4.0.1.0
oraclejd_edwards_enterpriseone_tools9.2
oraclejdeveloper11.1.1.9.0
oraclejdeveloper12.1.3.0.0
oraclejdeveloper12.2.1.3.0
oraclemysql_enterprise_monitor{"startIncluding":"3.4.0.0","endIncluding":"3.4.7.4297"}
oraclepeoplesoft_enterprise_fin_install9.2
oraclepolicy_automation10.4.7
oraclepolicy_automation12.1.0
oraclepolicy_automation12.1.1
oraclepolicy_automation12.2.0
oraclepolicy_automation12.2.1
oraclepolicy_automation12.2.2
oraclepolicy_automation12.2.3
oraclepolicy_automation12.2.4
oraclepolicy_automation12.2.5
oraclepolicy_automation12.2.6
oraclepolicy_automation12.2.7
oraclepolicy_automation12.2.8
oraclepolicy_automation12.2.9
oraclepolicy_automation12.2.10
oraclepolicy_automation_connector_for_siebel10.4.6
oraclepolicy_automation_for_mobile_devices10.4.7
oraclepolicy_automation_for_mobile_devices12.1.0
oraclepolicy_automation_for_mobile_devices12.1.1
oraclepolicy_automation_for_mobile_devices12.2.0
oraclepolicy_automation_for_mobile_devices12.2.1
oraclepolicy_automation_for_mobile_devices12.2.2
oraclepolicy_automation_for_mobile_devices12.2.3
oraclepolicy_automation_for_mobile_devices12.2.4
oraclepolicy_automation_for_mobile_devices12.2.5
oraclepolicy_automation_for_mobile_devices12.2.6
oraclepolicy_automation_for_mobile_devices12.2.7
oraclepolicy_automation_for_mobile_devices12.2.8
oraclepolicy_automation_for_mobile_devices12.2.9
oraclepolicy_automation_for_mobile_devices12.2.10
oracleprimavera_gateway{"startIncluding":"16.2.0","endIncluding":"16.2.11"}
oraclerapid_planning12.1
oraclerapid_planning12.2
oracleretail_advanced_inventory_planning14.0
oracleretail_advanced_inventory_planning15.0
oracleretail_clearance_optimization_engine14.0.5
oracleretail_extract_transform_and_load13.0
oracleretail_extract_transform_and_load13.1
oracleretail_extract_transform_and_load19.0
oracleretail_integration_bus14.0.0
oracleretail_integration_bus14.1.0
oracleretail_integration_bus15.0
oracleretail_integration_bus16.0
oracleretail_open_commerce_platform5.3.0
oracleretail_open_commerce_platform6.0.0
oracleretail_open_commerce_platform6.0.1
oracleretail_predictive_application_server15.0.3
oracleretail_service_backbone14.1
oracleretail_service_backbone15.0
oracleretail_service_backbone16.0
oraclesiebel_ui_framework18.7
oraclesiebel_ui_framework18.8
oraclesiebel_ui_framework18.9
oraclesoa_suite12.1.3.0.0
oraclesoa_suite12.2.1.3.0
oraclesoa_suite12.2.2.0.0
oracletape_library_acsls8.4
oracletimesten_in-memory_database11.2.2.8.49
oracleutilities_advanced_spatial_and_operational_analytics2.7.0.1
oracleutilities_work_and_asset_management1.9.1.2.12
oracleweblogic_server10.3.6.0.0
oracleweblogic_server12.1.3.0.0
oracleweblogic_server12.2.1.3.0
oracleweblogic_server12.2.1.4.0
oracleweblogic_server14.1.1.0.0

References

CWEs

CWE-502

Verify integrity in audit chain (admin only). AS-IS.