In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Log4j
APPApache2.0 – 2.8.2 (excl.)Netapp Oncommand Api Services
APPNetappall versionsNetapp Oncommand Insight
APPNetappall versionsNetapp Oncommand Workflow Automation
APPNetappall versionsNetapp Service Level Manager
APPNetappall versionsNetapp Snapcenter
APPNetappall versionsNetapp Storage Automation Store
APPNetappall versionsOracle Api Gateway
APPOracle11.1.2.4.0Oracle Application Testing Suite
APPOracle13.3.0.1Oracle Autovue Vuelink Integration
APPOracle21.0.021.0.1Oracle Banking Platform
APPOracle2.6.02.6.12.6.2Oracle Bi Publisher
APPOracle11.1.1.7.011.1.1.9.012.2.1.3.012.2.1.4.0Oracle Communications Converged Application Server Service Controller
APPOracle6.1Oracle Communications Instant Messaging Server
APPOracle10.0.1.3.0Oracle Communications Interactive Session Recorder
APPOracle6.0 – 6.2Oracle Communications Messaging Server
APPOracle< 8.0.2Oracle Communications Network Integrity
APPOracle7.3.2 – 7.3.6Oracle Communications Online Mediation Controller
APPOracle6.1Oracle Communications Pricing Design Center
APPOracle11.112.0Oracle Communications Service Broker
APPOracle6.0Oracle Communications Webrtc Session Controller
APPOracle< 7.2Oracle Configuration Manager
APPOracle12.1.2.0.212.1.2.0.5Oracle Endeca Information Discovery Studio
APPOracle3.2.0Oracle Enterprise Data Quality
APPOracle12.2.1.3.0Oracle Enterprise Manager Base Platform
APPOracle12.1.0.513.2.0.0Oracle Enterprise Manager For Fusion Middleware
APPOracle12.1.0.513.2.0.0Oracle Enterprise Manager For MySQL Database
APPOracle≤ 13.2.2.0.0Oracle Enterprise Manager For Oracle Database
APPOracle12.1.0.813.2.2Oracle Enterprise Manager For Peoplesoft
APPOracle13.1.1.113.2.1.1Oracle Financial Services Analytical Applications Infrastructure
APPOracle8.0.0.0.0 – 8.0.7.0.07.3.3.0.0 – 7.3.3.0.2
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEDeserialization
CWE
References
Related vulnerabilities
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2022-22963CRITICAL9.8⚠ KEVPL ✓same product
RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2021-45046CRITICAL9.0⚠ KEVPL ✓same product
Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup