CVE-2017-5645: Apache LOG4J

Critical severity, CVSS 9.8. EPSS: 89.8% chance of exploitation in the next 30 days.

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

Affected products

  • Apache LOG4J: from 2.0, before 2.8.2 (fixed in 2.8.2)
  • Netapp Oncommand API Services: affected versions not specified
  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Service Level Manager: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Netapp Storage Automation Store: affected versions not specified
  • Oracle API Gateway: version 11.1.2.4.0 only
  • Oracle Application Testing Suite: version 13.3.0.1 only
  • Oracle Autovue Vuelink Integration: version 21.0.0 only; version 21.0.1 only
  • Oracle Banking Platform: version 2.6.0 only; version 2.6.1 only; version 2.6.2 only
  • Oracle BI Publisher: version 11.1.1.7.0 only; version 11.1.1.9.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Communications Converged Application Server - Service Controller: version 6.1 only
  • Oracle Communications Instant Messaging Server: version 10.0.1.3.0 only
  • Oracle Communications Interactive Session Recorder: from 6.0, up to and including 6.2
  • Oracle Communications Messaging Server: before 8.0.2 (fixed in 8.0.2)
  • Oracle Communications Network Integrity: from 7.3.2, up to and including 7.3.6
  • Oracle Communications Online Mediation Controller: version 6.1 only
  • Oracle Communications Pricing Design Center: version 11.1 only; version 12.0 only
  • Oracle Communications Service Broker: version 6.0 only
  • Oracle Communications WebRTC Session Controller: before 7.2 (fixed in 7.2)
  • Oracle Configuration Manager: version 12.1.2.0.2 only; version 12.1.2.0.5 only
  • Oracle Endeca Information Discovery Studio: version 3.2.0 only
  • Oracle Enterprise Data Quality: version 12.2.1.3.0 only
  • Oracle Enterprise Manager Base Platform: version 12.1.0.5 only; version 13.2.0.0 only
  • and 54 more

Published 2017-04-17. Last modified 2026-10-08.