← volver
CVE-2017-5645

CVE-2017-5645

40Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendepss 90%
probabilidad de explotación
90%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
11 productos (14 componentes)
Red Hat Enterprise Linux 6 · Red Hat AMQ Broker 7 · Red Hat Enterprise Linux 5 · Red Hat Enterprise Virtualization 3 · Red Hat JBoss A-MQ 6 · y otros 6
none_available: Affected
Corregido
32 productos (745 componentes)
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server · Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5 Server · Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Server · Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server · Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server · y otros 27
No afectado
7 productosporque el código vulnerable no está presente en el producto
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools · Red Hat JBoss Data Virtualization 6 · Red Hat JBoss Operations Network 3 · Red Hat Mobile Application Platform 4 · Red Hat OpenShift Enterprise 3 · y otros 2
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.