Aller au contenu

Fiche vulnérabilité

CVE-2022-23302 : faille élevée apache log4j (CVSS 8.8)

Description

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
18 janv. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • apache log4j
  • netapp snapmanager
  • broadcom brocade sannav
  • qos reload4j
  • oracle advanced supply chain planning
  • oracle business intelligence
  • oracle business process management suite
  • oracle communications eagle ftp table base retrieval
  • oracle communications instant messaging server
  • oracle communications messaging server
  • oracle communications network integrity
  • oracle communications offline mediation controller
  • oracle communications unified inventory management
  • oracle e-business suite cloud manager and cloud backup module
  • oracle enterprise manager base platform
  • oracle financial services revenue management and billing analytics
  • oracle healthcare foundation
  • oracle hyperion data relationship management
  • oracle hyperion infrastructure technology
  • oracle identity management suite

Références

Rechercher une autre vulnérabilité dans la base CVE