CVE-2022-23302 (CNNVD-202201-1420)
中文标题:
Apache Log4j 代码问题漏洞
英文标题:
Deserialization of untrusted data in JMSSink in Apache Log4j 1.x
漏洞描述
中文描述:
Apache Log4j是美国阿帕奇(Apache)基金会的一款基于Java的开源日志记录工具。 Log4j 存在代码问题漏洞,该漏洞源于当攻击者对 Log4j 配置具有写访问权限或配置引用攻击者有权访问的 LDAP 服务时,所有 Log4j 1.x 版本中的 JMSSink 都容易受到不受信任数据的反序列化。 攻击者可以提供一个 TopicConnectionFactoryBindingName 配置,使 JMSSink 执行 JNDI 请求,从而以类似于 CVE-2021-4104 的方式执行远程代码。 请注意,此问题仅在专门配置为使用 JMSSink(不是默认设置)时影响 Log4j 1.x。 Apache Log4j 1.2 已于 2015 年 8 月结束生命周期。用户应升级到 Log4j 2,因为它解决了以前版本中的许多其他问题。
英文描述:
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Apache Software Foundation | Apache Log4j 1.x | - | < unspecified | - |
cpe:2.3:a:apache_software_foundation:apache_log4j_1.x:*:*:*:*:*:*:*:*
|
| apache | log4j | * | - | - |
cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
|
| netapp | snapmanager | - | - | - |
cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:*
|
| broadcom | brocade_sannav | - | - | - |
cpe:2.3:a:broadcom:brocade_sannav:-:*:*:*:*:*:*:*
|
| qos | reload4j | * | - | - |
cpe:2.3:a:qos:reload4j:*:*:*:*:*:*:*:*
|
| oracle | advanced_supply_chain_planning | 12.1 | - | - |
cpe:2.3:a:oracle:advanced_supply_chain_planning:12.1:*:*:*:*:*:*:*
|
| oracle | advanced_supply_chain_planning | 12.2 | - | - |
cpe:2.3:a:oracle:advanced_supply_chain_planning:12.2:*:*:*:*:*:*:*
|
| oracle | business_intelligence | 5.9.0.0.0 | - | - |
cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:*
|
| oracle | business_intelligence | 12.2.1.3.0 | - | - |
cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*
|
| oracle | business_intelligence | 12.2.1.4.0 | - | - |
cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
|
| oracle | business_process_management_suite | 12.2.1.3.0 | - | - |
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
|
| oracle | business_process_management_suite | 12.2.1.4.0 | - | - |
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
|
| oracle | communications_eagle_ftp_table_base_retrieval | 4.5 | - | - |
cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5:*:*:*:*:*:*:*
|
| oracle | communications_instant_messaging_server | 10.0.1.5.0 | - | - |
cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.5.0:*:*:*:*:*:*:*
|
| oracle | communications_messaging_server | 8.1 | - | - |
cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*
|
| oracle | communications_network_integrity | 7.3.6 | - | - |
cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*
|
| oracle | communications_offline_mediation_controller | * | - | - |
cpe:2.3:a:oracle:communications_offline_mediation_controller:*:*:*:*:*:*:*:*
|
| oracle | communications_offline_mediation_controller | 12.0.0.5.0 | - | - |
cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.5.0:*:*:*:*:*:*:*
|
| oracle | communications_unified_inventory_management | 7.4.1 | - | - |
cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:*
|
| oracle | communications_unified_inventory_management | 7.4.2 | - | - |
cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2:*:*:*:*:*:*:*
|
| oracle | e-business_suite_cloud_manager_and_cloud_backup_module | * | - | - |
cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:*:*:*:*:*:*:*:*
|
| oracle | e-business_suite_cloud_manager_and_cloud_backup_module | 2.2.1.1.1 | - | - |
cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:2.2.1.1.1:*:*:*:*:*:*:*
|
| oracle | enterprise_manager_base_platform | 13.4.0.0 | - | - |
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:*
|
| oracle | enterprise_manager_base_platform | 13.5.0.0 | - | - |
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0:*:*:*:*:*:*:*
|
| oracle | financial_services_revenue_management_and_billing_analytics | 2.7.0.0 | - | - |
cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.0:*:*:*:*:*:*:*
|
| oracle | financial_services_revenue_management_and_billing_analytics | 2.7.0.1 | - | - |
cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.1:*:*:*:*:*:*:*
|
| oracle | financial_services_revenue_management_and_billing_analytics | 2.8.0.0 | - | - |
cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.8.0.0:*:*:*:*:*:*:*
|
| oracle | healthcare_foundation | 8.1.0 | - | - |
cpe:2.3:a:oracle:healthcare_foundation:8.1.0:*:*:*:*:*:*:*
|
| oracle | hyperion_data_relationship_management | * | - | - |
cpe:2.3:a:oracle:hyperion_data_relationship_management:*:*:*:*:*:*:*:*
|
| oracle | hyperion_infrastructure_technology | * | - | - |
cpe:2.3:a:oracle:hyperion_infrastructure_technology:*:*:*:*:*:*:*:*
|
| oracle | identity_management_suite | 12.2.1.3.0 | - | - |
cpe:2.3:a:oracle:identity_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
|
| oracle | identity_management_suite | 12.2.1.4.0 | - | - |
cpe:2.3:a:oracle:identity_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
|
| oracle | identity_manager_connector | 11.1.1.5.0 | - | - |
cpe:2.3:a:oracle:identity_manager_connector:11.1.1.5.0:*:*:*:*:*:*:*
|
| oracle | jdeveloper | 12.2.1.3.0 | - | - |
cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:*
|
| oracle | middleware_common_libraries_and_tools | 12.2.1.4.0 | - | - |
cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*
|
| oracle | mysql_enterprise_monitor | * | - | - |
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
|
| oracle | tuxedo | 12.2.2.0.0 | - | - |
cpe:2.3:a:oracle:tuxedo:12.2.2.0.0:*:*:*:*:*:*:*
|
| oracle | weblogic_server | 12.2.1.3.0 | - | - |
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
|
| oracle | weblogic_server | 12.2.1.4.0 | - | - |
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
|
| oracle | weblogic_server | 14.1.1.0.0 | - | - |
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
nvd.nist.gov
nvd.nist.gov
CVSS评分详情
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2022-23302 |
2025-11-11 15:21:18 | 2025-11-11 07:37:20 |
| NVD | nvd_CVE-2022-23302 |
2025-11-11 14:58:13 | 2025-11-11 07:45:36 |
| CNNVD | cnnvd_CNNVD-202201-1420 |
2025-11-11 15:10:48 | 2025-11-11 07:57:04 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码问题
- cnnvd_id: 未提取 -> CNNVD-202201-1420
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 8.8
- cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.1
- affected_products_count: 2 -> 40
- references_count: 6 -> 8
- data_sources: ['cve'] -> ['cve', 'nvd']