VDB
BDU%3A2021-01051
BDU%3A2021-01051
PUBLISHED
CVSS 10 CRITICAL
Уязвимость библиотеки журналирования Java-программ Log4j, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corp., Apache Software Foundation | WebLogic Server, Enterprise Manager Ops Center, Enterprise Repository, Retail Back Office, Retail Central Office, Retail Returns Management, Retail Point-of-Service, JD Edwards EnterpriseOne Tools, Managed File Transfer, Oracle Endeca Information Discovery Integrator, Oracle JDeveloper, Oracle Retail Invoice Matching, Oracle Retail Order Broker, Instantis EnterpriseTrack, Communications WebRTC Session Controller, Endeca Server, JD Edwards World Security, Utilities Framework, Application Testing Suite, Communications Instant Messaging Server, Oracle Communications Interactive Session Recorder, Oracle Endeca Information Discovery Studio, Communications Online Mediation Controller, Retail Integration Bus, Communications Converged Application Server, Oracle Communications Service Broker, Primavera Gateway, Oracle Big Data Discovery, Identity Manager Connector, Retail Advanced Inventory Planning, MICROS Lucas, Tape Library ACSLS, Oracle Retail Service Backbone, Rapid Planning, Oracle FLEXCUBE Investor Servicing, Oracle FLEXCUBE Private Banking, Oracle Communications Network Integrity, Oracle Financial Services Lending and Leasing, Oracle Retail Extract Transform and Load, Communications Diameter Signaling Router, FLEXCUBE Core Banking, Oracle TimesTen In-Memory Database, Oracle Communications ASAP, Log4j, Oracle Communications Pricing Design Center, Oracle GoldenGate Application Adapters, Financial Services Compliance Regulatory Reporting, Oracle Communications Unified Inventory Management, Retail Xstore Point of Service |
Timeline
- Mar 2, 2021 CVE Published
- Dec 16, 2021 CVE Updated
References
- https://www.oracle.com/security-alerts/cpujan2021.html url
- https://www.oracle.com/security-alerts/cpuapr2020.html url
- https://www.oracle.com/security-alerts/cpujan2020.html url
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html url
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html url
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html url
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html url
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html url
- https://lists.apache.org/thread.html/0dcca05274d20ef2d72584edcf8c917bbb13dbbd7eb35cae909d02e9@%3Cdev.logging.apache.org%3E url
- https://lists.apache.org/thread.html/277b4b5c2b0e06a825ccec565fa65bd671f35a4d58e3e2ec5d0618e1@%3Cdev.tika.apache.org%3E url
- https://lists.apache.org/thread.html/44491fb9cc19acc901f7cff34acb7376619f15638439416e3e14761c@%3Cdev.tika.apache.org%3E url
- https://lists.apache.org/thread.html/479471e6debd608c837b9815b76eab24676657d4444fcfd5ef96d6e6@%3Cdev.tika.apache.org%3E url
- https://lists.apache.org/thread.html/6114ce566200d76e3cc45c521a62c2c5a4eac15738248f58a99f622c@%3Cissues.activemq.apache.org%3E url
- https://lists.apache.org/thread.html/84cc4266238e057b95eb95dfd8b29d46a2592e7672c12c92f68b2917@%3Cannounce.apache.org%3E url
- https://lists.apache.org/thread.html/8ab32b4c9f1826f20add7c40be08909de9f58a89dc1de9c09953f5ac@%3Cissues.activemq.apache.org%3E url
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommit.druid.apache.org%3E url
- https://lists.apache.org/thread.html/e8fb7d76a244ee997ba4b217d6171227f7c2521af8c7c5b16cba27bc@%3Cdev.logging.apache.org%3E url
- https://lists.apache.org/thread.html/eea03d504b36e8f870e8321d908e1def1addda16adda04327fe7c125@%3Cdev.logging.apache.org%3E url
- https://lists.apache.org/thread.html/r18f1c010b554a3a2d761e8ffffd8674fd4747bcbcf16c643d708318c@%3Cissues.activemq.apache.org%3E url
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E url
…and 27 more