CYBER CODE RED

Get real-time updates on Telegram

P2Verified

CVE-2017-5645: log4j from 2.0 (inclusive), before 2.8.2 (exclusive); +79 more affected products

CVE-2017-5645. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.89792 (percentile 0.9979), scored 2026-10-08.

Affected technology

log4j · from 2.0 (inclusive), before 2.8.2 (exclusive)
apache

oncommand api services · Version not applicable in the source CPE
netapp

oncommand insight · Version not applicable in the source CPE
netapp

oncommand workflow automation · Version not applicable in the source CPE
netapp

service level manager · Version not applicable in the source CPE
netapp

snapcenter · Version not applicable in the source CPE
netapp

storage automation store · Version not applicable in the source CPE
netapp

fuse · 1.0
redhat

enterprise linux · 6.0
redhat

enterprise linux · 6.7
redhat

enterprise linux · 7.0
redhat

enterprise linux · 7.3
redhat

enterprise linux · 7.4
redhat

enterprise linux · 7.5
redhat

enterprise linux · 7.6
redhat

enterprise linux desktop · 7.0
redhat

enterprise linux server · 7.0
redhat

enterprise linux server aus · 7.4
redhat

enterprise linux server aus · 7.6
redhat

enterprise linux server eus · 7.4
redhat

enterprise linux server eus · 7.5
redhat

enterprise linux server eus · 7.6
redhat

enterprise linux server tus · 7.4
redhat

enterprise linux server tus · 7.6
redhat

enterprise linux workstation · 7.0
redhat

api gateway · 11.1.2.4.0
oracle

application testing suite · 13.3.0.1
oracle

autovue vuelink integration · 21.0.0
oracle

autovue vuelink integration · 21.0.1
oracle

banking platform · 2.6.0
oracle

banking platform · 2.6.1
oracle

banking platform · 2.6.2
oracle

bi publisher · 11.1.1.7.0
oracle

bi publisher · 11.1.1.9.0
oracle

bi publisher · 12.2.1.3.0
oracle

bi publisher · 12.2.1.4.0
oracle

communications converged application server - service controller · 6.1
oracle

communications instant messaging server · 10.0.1.3.0
oracle

communications interactive session recorder · from 6.0 (inclusive), through 6.2 (inclusive)
oracle

communications messaging server · before 8.0.2 (exclusive)
oracle

communications network integrity · from 7.3.2 (inclusive), through 7.3.6 (inclusive)
oracle

communications online mediation controller · 6.1
oracle

communications pricing design center · 11.1
oracle

communications pricing design center · 12.0
oracle

communications service broker · 6.0
oracle

communications webrtc session controller · before 7.2 (exclusive)
oracle

configuration manager · 12.1.2.0.2
oracle

configuration manager · 12.1.2.0.5
oracle

endeca information discovery studio · 3.2.0
oracle

enterprise data quality · 12.2.1.3.0
oracle

enterprise manager base platform · 12.1.0.5
oracle

enterprise manager base platform · 13.2.0.0
oracle

enterprise manager for fusion middleware · 12.1.0.5
oracle

enterprise manager for fusion middleware · 13.2.0.0
oracle

enterprise manager for mysql database · through 13.2.2.0.0 (inclusive)
oracle

enterprise manager for oracle database · 12.1.0.8
oracle

enterprise manager for oracle database · 13.2.2
oracle

enterprise manager for peoplesoft · 13.1.1.1
oracle

enterprise manager for peoplesoft · 13.2.1.1
oracle

financial services analytical applications infrastructure · from 7.3.3.0.0 (inclusive), through 7.3.3.0.2 (inclusive)
oracle

financial services analytical applications infrastructure · from 8.0.0.0.0 (inclusive), through 8.0.7.0.0 (inclusive)
oracle

financial services behavior detection platform · from 8.0.0.0.0 (inclusive), through 8.0.4.0.0 (inclusive)
oracle

financial services behavior detection platform · 6.1.1
oracle

financial services hedge management and ifrs valuations · 8.0.4
oracle

financial services hedge management and ifrs valuations · 8.0.5
oracle

financial services lending and leasing · from 14.1.0 (inclusive), through 14.8.0 (inclusive)
oracle

financial services lending and leasing · 12.5.0
oracle

financial services loan loss forecasting and provisioning · 8.0.4
oracle

financial services loan loss forecasting and provisioning · 8.0.5
oracle

financial services profitability management · from 8.0.0.0.0 (inclusive), through 8.0.7.0.0 (inclusive)
oracle

financial services profitability management · 6.1.1
oracle

financial services regulatory reporting with agilereporter · 8.0.9.2.0
oracle

flexcube investor servicing · 12.0.4
oracle

flexcube investor servicing · 12.1.0
oracle

flexcube investor servicing · 12.3.0
oracle

flexcube investor servicing · 12.4.0
oracle

flexcube investor servicing · 14.0.0
oracle

fusion middleware mapviewer · 12.2.1.2
oracle

fusion middleware mapviewer · 12.2.1.3
oracle

goldengate · 12.3.2.1.1
oracle

goldengate application adapters · 12.3.2.1.1
oracle

identity analytics · 11.1.1.5.8
oracle

identity management suite · 11.1.2.3.0
oracle

identity management suite · 12.2.1.3.0
oracle

identity manager connector · 9.0
oracle

in-memory performance-driven planning · 12.1
oracle

in-memory performance-driven planning · 12.2
oracle

instantis enterprisetrack · from 17.1 (inclusive), through 17.3 (inclusive)
oracle

insurance calculation engine · 10.1.1
oracle

insurance calculation engine · 10.2.1
oracle

insurance policy administration · 10.0
oracle

insurance policy administration · 10.1
oracle

insurance policy administration · 10.2
oracle

insurance policy administration · 11.0
oracle

insurance rules palette · 10.0
oracle

insurance rules palette · 10.1
oracle

insurance rules palette · 10.2
oracle

insurance rules palette · 11.0
oracle

insurance rules palette · 11.1
oracle

jd edwards enterpriseone tools · 4.0.1.0
oracle

jd edwards enterpriseone tools · 9.2
oracle

jdeveloper · 11.1.1.9.0
oracle

jdeveloper · 12.1.3.0.0
oracle

jdeveloper · 12.2.1.3.0
oracle

mysql enterprise monitor · from 3.4.0.0 (inclusive), through 3.4.7.4297 (inclusive)
oracle

mysql enterprise monitor · from 4.0.0.0 (inclusive), through 4.0.4.5235 (inclusive)
oracle

mysql enterprise monitor · from 8.0.0.0.0 (inclusive), through 8.0.0.8131 (inclusive)
oracle

peoplesoft enterprise fin install · 9.2
oracle

policy automation · 10.4.7
oracle

policy automation · 12.1.0
oracle

policy automation · 12.1.1
oracle

policy automation · 12.2.0
oracle

policy automation · 12.2.1
oracle

policy automation · 12.2.2
oracle

policy automation · 12.2.3
oracle

policy automation · 12.2.4
oracle

policy automation · 12.2.5
oracle

policy automation · 12.2.6
oracle

policy automation · 12.2.7
oracle

policy automation · 12.2.8
oracle

policy automation · 12.2.9
oracle

policy automation · 12.2.10
oracle

policy automation connector for siebel · 10.4.6
oracle

policy automation for mobile devices · 10.4.7
oracle

policy automation for mobile devices · 12.1.0
oracle

policy automation for mobile devices · 12.1.1
oracle

policy automation for mobile devices · 12.2.0
oracle

policy automation for mobile devices · 12.2.1
oracle

policy automation for mobile devices · 12.2.2
oracle

policy automation for mobile devices · 12.2.3
oracle

policy automation for mobile devices · 12.2.4
oracle

policy automation for mobile devices · 12.2.5
oracle

policy automation for mobile devices · 12.2.6
oracle

policy automation for mobile devices · 12.2.7
oracle

policy automation for mobile devices · 12.2.8
oracle

policy automation for mobile devices · 12.2.9
oracle

policy automation for mobile devices · 12.2.10
oracle

primavera gateway · from 16.2.0 (inclusive), through 16.2.11 (inclusive)
oracle

primavera gateway · from 17.12.0 (inclusive), through 17.12.7 (inclusive)
oracle

rapid planning · 12.1
oracle

rapid planning · 12.2
oracle

retail advanced inventory planning · 14.0
oracle

retail advanced inventory planning · 15.0
oracle

retail clearance optimization engine · 14.0.5
oracle

retail extract transform and load · 13.0
oracle

retail extract transform and load · 13.1
oracle

retail extract transform and load · 13.2
oracle

retail extract transform and load · 19.0
oracle

retail integration bus · 14.0.0
oracle

retail integration bus · 14.1.0
oracle

retail integration bus · 15.0
oracle

retail integration bus · 16.0
oracle

retail open commerce platform · 5.3.0
oracle

retail open commerce platform · 6.0.0
oracle

retail open commerce platform · 6.0.1
oracle

retail predictive application server · 15.0.3
oracle

retail service backbone · 14.1
oracle

retail service backbone · 15.0
oracle

retail service backbone · 16.0
oracle

siebel ui framework · 18.7
oracle

siebel ui framework · 18.8
oracle

siebel ui framework · 18.9
oracle

soa suite · 12.1.3.0.0
oracle

soa suite · 12.2.1.3.0
oracle

soa suite · 12.2.2.0.0
oracle

tape library acsls · 8.4
oracle

timesten in-memory database · 11.2.2.8.49
oracle

utilities advanced spatial and operational analytics · 2.7.0.1
oracle

utilities work and asset management · 1.9.1.2.12
oracle

weblogic server · 10.3.6.0.0
oracle

weblogic server · 12.1.3.0.0
oracle

weblogic server · 12.2.1.3.0
oracle

weblogic server · 12.2.1.4.0
oracle

weblogic server · 14.1.1.0.0
oracle

Apache Log4j · All versions between 2.0-alpha1 and 2.8.1
Apache Software Foundation

Description’s affected range: before 2.8.2

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could run attacker-chosen code under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-502
CCR priority
61.6 /100 (P2)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.89792 · percentile 0.9979 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2017-5645.html