Get real-time updates on Telegram
CVE-2017-5645: log4j from 2.0 (inclusive), before 2.8.2 (exclusive); +79 more affected products
CVE-2017-5645. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.89792 (percentile 0.9979), scored 2026-10-08.
Affected technology
log4j · from 2.0 (inclusive), before 2.8.2 (exclusive)
apache
oncommand api services · Version not applicable in the source CPE
netapp
oncommand insight · Version not applicable in the source CPE
netapp
oncommand workflow automation · Version not applicable in the source CPE
netapp
service level manager · Version not applicable in the source CPE
netapp
snapcenter · Version not applicable in the source CPE
netapp
storage automation store · Version not applicable in the source CPE
netapp
fuse · 1.0
redhat
enterprise linux · 6.0
redhat
enterprise linux · 6.7
redhat
enterprise linux · 7.0
redhat
enterprise linux · 7.3
redhat
enterprise linux · 7.4
redhat
enterprise linux · 7.5
redhat
enterprise linux · 7.6
redhat
enterprise linux desktop · 7.0
redhat
enterprise linux server · 7.0
redhat
enterprise linux server aus · 7.4
redhat
enterprise linux server aus · 7.6
redhat
enterprise linux server eus · 7.4
redhat
enterprise linux server eus · 7.5
redhat
enterprise linux server eus · 7.6
redhat
enterprise linux server tus · 7.4
redhat
enterprise linux server tus · 7.6
redhat
enterprise linux workstation · 7.0
redhat
api gateway · 11.1.2.4.0
oracle
application testing suite · 13.3.0.1
oracle
autovue vuelink integration · 21.0.0
oracle
autovue vuelink integration · 21.0.1
oracle
banking platform · 2.6.0
oracle
banking platform · 2.6.1
oracle
banking platform · 2.6.2
oracle
bi publisher · 11.1.1.7.0
oracle
bi publisher · 11.1.1.9.0
oracle
bi publisher · 12.2.1.3.0
oracle
bi publisher · 12.2.1.4.0
oracle
communications converged application server - service controller · 6.1
oracle
communications instant messaging server · 10.0.1.3.0
oracle
communications interactive session recorder · from 6.0 (inclusive), through 6.2 (inclusive)
oracle
communications messaging server · before 8.0.2 (exclusive)
oracle
communications network integrity · from 7.3.2 (inclusive), through 7.3.6 (inclusive)
oracle
communications online mediation controller · 6.1
oracle
communications pricing design center · 11.1
oracle
communications pricing design center · 12.0
oracle
communications service broker · 6.0
oracle
communications webrtc session controller · before 7.2 (exclusive)
oracle
configuration manager · 12.1.2.0.2
oracle
configuration manager · 12.1.2.0.5
oracle
endeca information discovery studio · 3.2.0
oracle
enterprise data quality · 12.2.1.3.0
oracle
enterprise manager base platform · 12.1.0.5
oracle
enterprise manager base platform · 13.2.0.0
oracle
enterprise manager for fusion middleware · 12.1.0.5
oracle
enterprise manager for fusion middleware · 13.2.0.0
oracle
enterprise manager for mysql database · through 13.2.2.0.0 (inclusive)
oracle
enterprise manager for oracle database · 12.1.0.8
oracle
enterprise manager for oracle database · 13.2.2
oracle
enterprise manager for peoplesoft · 13.1.1.1
oracle
enterprise manager for peoplesoft · 13.2.1.1
oracle
financial services analytical applications infrastructure · from 7.3.3.0.0 (inclusive), through 7.3.3.0.2 (inclusive)
oracle
financial services analytical applications infrastructure · from 8.0.0.0.0 (inclusive), through 8.0.7.0.0 (inclusive)
oracle
financial services behavior detection platform · from 8.0.0.0.0 (inclusive), through 8.0.4.0.0 (inclusive)
oracle
financial services behavior detection platform · 6.1.1
oracle
financial services hedge management and ifrs valuations · 8.0.4
oracle
financial services hedge management and ifrs valuations · 8.0.5
oracle
financial services lending and leasing · from 14.1.0 (inclusive), through 14.8.0 (inclusive)
oracle
financial services lending and leasing · 12.5.0
oracle
financial services loan loss forecasting and provisioning · 8.0.4
oracle
financial services loan loss forecasting and provisioning · 8.0.5
oracle
financial services profitability management · from 8.0.0.0.0 (inclusive), through 8.0.7.0.0 (inclusive)
oracle
financial services profitability management · 6.1.1
oracle
financial services regulatory reporting with agilereporter · 8.0.9.2.0
oracle
flexcube investor servicing · 12.0.4
oracle
flexcube investor servicing · 12.1.0
oracle
flexcube investor servicing · 12.3.0
oracle
flexcube investor servicing · 12.4.0
oracle
flexcube investor servicing · 14.0.0
oracle
fusion middleware mapviewer · 12.2.1.2
oracle
fusion middleware mapviewer · 12.2.1.3
oracle
goldengate · 12.3.2.1.1
oracle
goldengate application adapters · 12.3.2.1.1
oracle
identity analytics · 11.1.1.5.8
oracle
identity management suite · 11.1.2.3.0
oracle
identity management suite · 12.2.1.3.0
oracle
identity manager connector · 9.0
oracle
in-memory performance-driven planning · 12.1
oracle
in-memory performance-driven planning · 12.2
oracle
instantis enterprisetrack · from 17.1 (inclusive), through 17.3 (inclusive)
oracle
insurance calculation engine · 10.1.1
oracle
insurance calculation engine · 10.2.1
oracle
insurance policy administration · 10.0
oracle
insurance policy administration · 10.1
oracle
insurance policy administration · 10.2
oracle
insurance policy administration · 11.0
oracle
insurance rules palette · 10.0
oracle
insurance rules palette · 10.1
oracle
insurance rules palette · 10.2
oracle
insurance rules palette · 11.0
oracle
insurance rules palette · 11.1
oracle
jd edwards enterpriseone tools · 4.0.1.0
oracle
jd edwards enterpriseone tools · 9.2
oracle
jdeveloper · 11.1.1.9.0
oracle
jdeveloper · 12.1.3.0.0
oracle
jdeveloper · 12.2.1.3.0
oracle
mysql enterprise monitor · from 3.4.0.0 (inclusive), through 3.4.7.4297 (inclusive)
oracle
mysql enterprise monitor · from 4.0.0.0 (inclusive), through 4.0.4.5235 (inclusive)
oracle
mysql enterprise monitor · from 8.0.0.0.0 (inclusive), through 8.0.0.8131 (inclusive)
oracle
peoplesoft enterprise fin install · 9.2
oracle
policy automation · 10.4.7
oracle
policy automation · 12.1.0
oracle
policy automation · 12.1.1
oracle
policy automation · 12.2.0
oracle
policy automation · 12.2.1
oracle
policy automation · 12.2.2
oracle
policy automation · 12.2.3
oracle
policy automation · 12.2.4
oracle
policy automation · 12.2.5
oracle
policy automation · 12.2.6
oracle
policy automation · 12.2.7
oracle
policy automation · 12.2.8
oracle
policy automation · 12.2.9
oracle
policy automation · 12.2.10
oracle
policy automation connector for siebel · 10.4.6
oracle
policy automation for mobile devices · 10.4.7
oracle
policy automation for mobile devices · 12.1.0
oracle
policy automation for mobile devices · 12.1.1
oracle
policy automation for mobile devices · 12.2.0
oracle
policy automation for mobile devices · 12.2.1
oracle
policy automation for mobile devices · 12.2.2
oracle
policy automation for mobile devices · 12.2.3
oracle
policy automation for mobile devices · 12.2.4
oracle
policy automation for mobile devices · 12.2.5
oracle
policy automation for mobile devices · 12.2.6
oracle
policy automation for mobile devices · 12.2.7
oracle
policy automation for mobile devices · 12.2.8
oracle
policy automation for mobile devices · 12.2.9
oracle
policy automation for mobile devices · 12.2.10
oracle
primavera gateway · from 16.2.0 (inclusive), through 16.2.11 (inclusive)
oracle
primavera gateway · from 17.12.0 (inclusive), through 17.12.7 (inclusive)
oracle
rapid planning · 12.1
oracle
rapid planning · 12.2
oracle
retail advanced inventory planning · 14.0
oracle
retail advanced inventory planning · 15.0
oracle
retail clearance optimization engine · 14.0.5
oracle
retail extract transform and load · 13.0
oracle
retail extract transform and load · 13.1
oracle
retail extract transform and load · 13.2
oracle
retail extract transform and load · 19.0
oracle
retail integration bus · 14.0.0
oracle
retail integration bus · 14.1.0
oracle
retail integration bus · 15.0
oracle
retail integration bus · 16.0
oracle
retail open commerce platform · 5.3.0
oracle
retail open commerce platform · 6.0.0
oracle
retail open commerce platform · 6.0.1
oracle
retail predictive application server · 15.0.3
oracle
retail service backbone · 14.1
oracle
retail service backbone · 15.0
oracle
retail service backbone · 16.0
oracle
siebel ui framework · 18.7
oracle
siebel ui framework · 18.8
oracle
siebel ui framework · 18.9
oracle
soa suite · 12.1.3.0.0
oracle
soa suite · 12.2.1.3.0
oracle
soa suite · 12.2.2.0.0
oracle
tape library acsls · 8.4
oracle
timesten in-memory database · 11.2.2.8.49
oracle
utilities advanced spatial and operational analytics · 2.7.0.1
oracle
utilities work and asset management · 1.9.1.2.12
oracle
weblogic server · 10.3.6.0.0
oracle
weblogic server · 12.1.3.0.0
oracle
weblogic server · 12.2.1.3.0
oracle
weblogic server · 12.2.1.4.0
oracle
weblogic server · 14.1.1.0.0
oracle
Apache Log4j · All versions between 2.0-alpha1 and 2.8.1
Apache Software Foundation
Description’s affected range: before 2.8.2
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
The source reports that an attacker could run attacker-chosen code under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-502
- CCR priority
- 61.6 /100 (P2)
- CVSS 3.1
- 9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.89792 · percentile 0.9979 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2017-5645.html