CVE-2017-5645 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
- 🔗 access.redhat.com/errata/RHSA-2017:2888
- 🔗 access.redhat.com/errata/RHSA-2017:2809
- 🔗 www.securityfocus.com/bid/97702
- 🔗 www.securitytracker.com/id/1041294
- 🔗 access.redhat.com/errata/RHSA-2017:2810
- 🔗 access.redhat.com/errata/RHSA-2017:1801
- 🔗 access.redhat.com/errata/RHSA-2017:2889
- 🔗 access.redhat.com/errata/RHSA-2017:2635
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | CVEs | Anteil |
|---|---|---|
| ≥90 % | 720 | 0,2 % |
| ≥50 % | 3.223 | 0,9 % |
| ≥10 % | 22.115 | 6,0 % |
| <10 % | 342.373 | 92,9 % |
CVE-2017-5645 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary
Noch keine Analyse zu CVE-2017-5645
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.