CVE-2019-17571: Apache Bookkeeper
Critical severity, CVSS 9.8. EPSS: 69.1% chance of exploitation in the next 30 days.
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
Affected products
- Apache Bookkeeper: before 4.14.3 (fixed in 4.14.3)
- Apache LOG4J: up to and including 1.2.17
- Canonical Ubuntu Linux: version 18.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
- Netapp Oncommand System Manager: from 3.0, up to and including 3.1.3
- Netapp Oncommand Workflow Automation: affected versions not specified
- Opensuse Leap: version 15.1 only
- Oracle Application Testing Suite: version 13.3.0.1 only
- Oracle Communications Network Integrity: from 7.3.2, up to and including 7.3.6
- Oracle Endeca Information Discovery Studio: version 3.2.0 only
- Oracle Financial Services Lending And Leasing: from 14.1.0, up to and including 14.8.0; version 12.5.0 only
- Oracle MySQL Enterprise Monitor: up to and including 8.0.29
- Oracle Primavera Gateway: from 16.2, up to and including 16.2.11; from 17.12.0, up to and including 17.12.7
- Oracle Rapid Planning: version 12.1 only; version 12.2 only
- Oracle Retail Extract Transform And Load: version 19.0 only
- Oracle Retail Service Backbone: version 14.1 only; version 15.0 only; version 16.0 only
- Oracle WebLogic Server: version 10.3.6.0.0 only; version 12.1.3.0.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only; version 14.1.1.0.0 only
Published 2019-12-20. Last modified 2026-06-17.