Vulnerability Details CVE-2022-23302
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.0
Products affected by CVE-2022-23302
-
cpe:2.3:a:apache:log4j:1.0.4
-
cpe:2.3:a:apache:log4j:1.1.3
-
cpe:2.3:a:apache:log4j:1.2
-
cpe:2.3:a:apache:log4j:1.2.1
-
cpe:2.3:a:apache:log4j:1.2.10
-
cpe:2.3:a:apache:log4j:1.2.11
-
cpe:2.3:a:apache:log4j:1.2.12
-
cpe:2.3:a:apache:log4j:1.2.13
-
cpe:2.3:a:apache:log4j:1.2.14
-
cpe:2.3:a:apache:log4j:1.2.15
-
cpe:2.3:a:apache:log4j:1.2.16
-
cpe:2.3:a:apache:log4j:1.2.17
-
cpe:2.3:a:apache:log4j:1.2.2
-
cpe:2.3:a:apache:log4j:1.2.3
-
cpe:2.3:a:apache:log4j:1.2.4
-
cpe:2.3:a:apache:log4j:1.2.5
-
cpe:2.3:a:apache:log4j:1.2.6
-
cpe:2.3:a:apache:log4j:1.2.7
-
cpe:2.3:a:apache:log4j:1.2.8
-
cpe:2.3:a:apache:log4j:1.2.9
-
cpe:2.3:a:broadcom:brocade_sannav:-
-
cpe:2.3:a:netapp:snapmanager:-
-
cpe:2.3:a:oracle:advanced_supply_chain_planning:12.1
-
cpe:2.3:a:oracle:advanced_supply_chain_planning:12.2
-
cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0
-
cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0
-
cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0
-
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0
-
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0
-
cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5
-
cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.5.0
-
cpe:2.3:a:oracle:communications_messaging_server:8.1
-
cpe:2.3:a:oracle:communications_network_integrity:7.3.6
-
cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3
-
cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3.0
-
cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.5.0
-
cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1
-
cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2
-
cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:*
-
cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:2.2.1.1.1
-
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0
-
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0
-
cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.0
-
cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.1
-
cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.8.0.0
-
cpe:2.3:a:oracle:healthcare_foundation:8.1.0
-
cpe:2.3:a:oracle:hyperion_data_relationship_management:-
-
cpe:2.3:a:oracle:hyperion_data_relationship_management:11.1.2.4
-
cpe:2.3:a:oracle:hyperion_data_relationship_management:11.1.2.4.330
-
cpe:2.3:a:oracle:hyperion_data_relationship_management:11.1.2.4.344
-
cpe:2.3:a:oracle:hyperion_data_relationship_management:11.1.2.4.345
-
cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4
-
cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.6.0
-
cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.5.0
-
cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.6.0
-
cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.7.0
-
cpe:2.3:a:oracle:identity_management_suite:12.2.1.3.0
-
cpe:2.3:a:oracle:identity_management_suite:12.2.1.4.0
-
cpe:2.3:a:oracle:identity_manager_connector:11.1.1.5.0
-
cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0
-
cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:-
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:2.3.14
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.0.25
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.0.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.3
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.3.7856
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.5
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.6
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.6.8003
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.1.7
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.10
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.1182
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.3
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.5
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.6
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.7
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.8
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.8.2223
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.9
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.2.1162
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.3
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.4.3247
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.5
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.6
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.6.3293
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.7
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.8
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.3.9
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.10
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.2.4181
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.3
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.4.4226
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.5
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.6
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.7
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.7.4297
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.8
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.9
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:3.4.9.4237
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.0.5135
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.11.5331
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.12
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.3
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.4
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.4.5235
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.5
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.6
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.6.5281
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.7
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.0.8
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:4.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.0
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.0.8131
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.1
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.14
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.18.1217
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.2
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.2.8191
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.20
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.21
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.22
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.23
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.25
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.29
-
cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.3
-
cpe:2.3:a:oracle:tuxedo:12.2.2.0.0
-
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0
-
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0
-
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0
-
cpe:2.3:a:qos:reload4j:1.0
-
cpe:2.3:a:qos:reload4j:1.0.1
-
cpe:2.3:a:qos:reload4j:1.0.4
-
cpe:2.3:a:qos:reload4j:1.1
-
cpe:2.3:a:qos:reload4j:1.1.1
-
cpe:2.3:a:qos:reload4j:1.1.2
-
cpe:2.3:a:qos:reload4j:1.1.3
-
cpe:2.3:a:qos:reload4j:1.2
-
cpe:2.3:a:qos:reload4j:1.2.1
-
cpe:2.3:a:qos:reload4j:1.2.11
-
cpe:2.3:a:qos:reload4j:1.2.12
-
cpe:2.3:a:qos:reload4j:1.2.13
-
cpe:2.3:a:qos:reload4j:1.2.14
-
cpe:2.3:a:qos:reload4j:1.2.15
-
cpe:2.3:a:qos:reload4j:1.2.16
-
cpe:2.3:a:qos:reload4j:1.2.17
-
cpe:2.3:a:qos:reload4j:1.2.18.0
-
cpe:2.3:a:qos:reload4j:1.2.2
-
cpe:2.3:a:qos:reload4j:1.2.3
-
cpe:2.3:a:qos:reload4j:1.2.4
-
cpe:2.3:a:qos:reload4j:1.2.6
-
cpe:2.3:a:qos:reload4j:1.2.7
-
cpe:2.3:a:qos:reload4j:1.2.9