Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.117902
Category:General
Title:Apache Log4j 1.x Multiple Vulnerabilities (Windows, Jan 2022) - Version Check
Summary:Apache Log4j is prone to multiple vulnerabilities.
Description:Summary:
Apache Log4j is prone to multiple vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- CVE-2022-23302: Deserialization of untrusted data in JMSSink. Note this issue only affects Log4j
1.x when specifically configured to use JMSSink, which is not the default.

- CVE-2022-23305: SQL injection in JDBC Appender. Note this issue only affects Log4j 1.x when
specifically configured to use the JDBCAppender, which is not the default.

- CVE-2022-23307/CVE-2020-9493: A deserialization flaw in the Chainsaw component of Log4j 1.x can
lead to malicious code execution.

Affected Software/OS:
Apache Log4j version 1.x.

Solution:
No solution was made available by the vendor.

Note: Apache Log4j 1.x reached end of life in August 2015. Users should upgrade to Log4j 2 as it
addresses numerous other issues from the previous versions.

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-23302
https://security.netapp.com/advisory/ntap-20220217-0006/
https://lists.apache.org/thread/bsr3l5qz4g0myrjhy9h67bcxodpkwj4w
https://logging.apache.org/log4j/1.2/index.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
http://www.openwall.com/lists/oss-security/2022/01/18/3
Common Vulnerability Exposure (CVE) ID: CVE-2022-23305
https://security.netapp.com/advisory/ntap-20220217-0007/
https://lists.apache.org/thread/pt6lh3pbsvxqlwlp4c5l798dv2hkc85y
http://www.openwall.com/lists/oss-security/2022/01/18/4
Common Vulnerability Exposure (CVE) ID: CVE-2022-23307
https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh
Common Vulnerability Exposure (CVE) ID: CVE-2020-9493
https://www.openwall.com/lists/oss-security/2021/06/16/1
https://lists.apache.org/thread.html/r50d389c613ba6062a26aa57e163c09bfee4ff2d95d67331d75265b83@%3Cannounce.apache.org%3E
http://www.openwall.com/lists/oss-security/2021/06/16/1
http://www.openwall.com/lists/oss-security/2022/01/18/5
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.