Fiche vulnérabilité
CVE-2022-23307 : faille élevée apache chainsaw (CVSS 8.8)
Description
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 18 janv. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- apache chainsaw
- apache log4j
- qos reload4j
- oracle advanced supply chain planning
- oracle business intelligence
- oracle business process management suite
- oracle communications eagle ftp table base retrieval
- oracle communications instant messaging server
- oracle communications messaging server
- oracle communications network integrity
- oracle communications offline mediation controller
- oracle communications unified inventory management
- oracle e-business suite cloud manager and cloud backup module
- oracle enterprise manager base platform
- oracle financial services revenue management and billing analytics
- oracle healthcare foundation
- oracle hyperion data relationship management
- oracle hyperion infrastructure technology
- oracle identity management suite
- oracle identity manager connector