CVE-2019-17571

CRITICAL WAF: Medium
CVSS 9.8 Published: 2019-12-20
CWE-502 CWE-502

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

WAF Coverage Analysis

Insecure Deserialization Medium WAF Coverage

OWASP: A08:2021 Software and Data Integrity Failures

944xxx - Java Attack
Insecure Deserialization Medium WAF Coverage

OWASP: A08:2021 Software and Data Integrity Failures

944xxx - Java Attack

Affected Software

VendorProductVersion
apachelog4jup to 1.2.17
debiandebian_linux8.0
debiandebian_linux9.0
debiandebian_linux10.0
canonicalubuntu_linux18.04
opensuseleap15.1
netapponcommand_system_manager3.0 - 3.1.3
netapponcommand_workflow_automation-
oracleapplication_testing_suite13.3.0.1
oraclecommunications_network_integrity7.3.2 - 7.3.6

References

Back to CVE Database