Fiche vulnérabilité
CVE-2022-23302 : faille élevée apache log4j (CVSS 8.8)
Description
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 18 janv. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- apache log4j
- netapp snapmanager
- broadcom brocade sannav
- qos reload4j
- oracle advanced supply chain planning
- oracle business intelligence
- oracle business process management suite
- oracle communications eagle ftp table base retrieval
- oracle communications instant messaging server
- oracle communications messaging server
- oracle communications network integrity
- oracle communications offline mediation controller
- oracle communications unified inventory management
- oracle e-business suite cloud manager and cloud backup module
- oracle enterprise manager base platform
- oracle financial services revenue management and billing analytics
- oracle healthcare foundation
- oracle hyperion data relationship management
- oracle hyperion infrastructure technology
- oracle identity management suite
Références
- Fiche CVE-2022-23302 sur le NVD (NIST)
- openwall.com/lists/oss-security/2022/01/18/3
- lists.apache.org/thread/bsr3l5qz4g0myrjhy9h67bcxodpkwj4w
- logging.apache.org/log4j/1.2/index.html
- security.netapp.com/advisory/ntap-20220217-0006/
- oracle.com/security-alerts/cpuapr2022.html
- oracle.com/security-alerts/cpujul2022.html
- vicarius.io/vsociety/posts/cve…
- vicarius.io/vsociety/posts/cve…