← back
CVE-2017-5645

CVE-2017-5645

40Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 90%
exploitation probability
90%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
11 products (14 components)
Red Hat Enterprise Linux 6 · Red Hat AMQ Broker 7 · Red Hat Enterprise Linux 5 · Red Hat Enterprise Virtualization 3 · Red Hat JBoss A-MQ 6 · and others 6
none_available: Affected
Fixed
32 products (745 components)
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server · Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5 Server · Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Server · Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server · Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server · and others 27
Not affected
7 productsbecause the vulnerable code is not present in the product
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools · Red Hat JBoss Data Virtualization 6 · Red Hat JBoss Operations Network 3 · Red Hat Mobile Application Platform 4 · Red Hat OpenShift Enterprise 3 · and others 2
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.