Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2022-23305: log4j can let attackers run code
CVE-2022-23305 · published 1 day ago
Summary
The log4j library used in several products can be tricked into executing arbitrary commands. Updating to the latest patched version removes this risk. Apply the vendor‑provided updates as soon as possible.
What to do
- Update root io.root.log4j:log4j to version 1.2.12-root.io.1.
- Update log4j:log4j to version 1.2.14-aikido.4.
- Update io.root.log4j:log4j to version 1.2.14-root.io.4.
- Update log4j:log4j to version 1.2.14-aikido.5.
- Update io.root.log4j:log4j to version 1.2.14-root.io.5.
- Update qos reload4j to version 1.2.18.2 or later.
- Update oracle communications_offline_mediation_controller to version 12.0.0.4.4 or later.
- Update oracle e-business_suite_cloud_manager_and_cloud_backup_module to version 2.2.1.1.1 or later.
- Update oracle hyperion_data_relationship_management to version 11.2.8.0 or later.
- Update oracle hyperion_infrastructure_technology to version 11.2.8.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| maven | log4j | log4j:log4j | <= 1.2.17 |
| maven | zenframework | org.zenframework.z8.dependencies.commons:log4j-1.2.17 | <= 2.0 |
| – | apache | log4j |
>= 1.2, <= 1.2.17 cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* |
| – | netapp | snapmanager |
All versions
cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:* |
| – | broadcom | brocade_sannav |
All versions
cpe:2.3:a:broadcom:brocade_sannav:-:*:*:*:*:*:*:* |
| – | qos | reload4j |
< 1.2.18.2 cpe:2.3:a:qos:reload4j:*:*:*:*:*:*:*:* |
| – | oracle | advanced_supply_chain_planning |
12.1 12.2 cpe:2.3:a:oracle:advanced_supply_chain_planning:12.1:*:*:*:*:*:*:* |
| – | oracle | business_intelligence |
5.9.0.0.0 12.2.1.3.0 12.2.1.4.0 cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:* |
| – | oracle | business_process_management_suite |
12.2.1.3.0 12.2.1.4.0 cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:* |
| – | oracle | communications_eagle_ftp_table_base_retrieval |
4.5 cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5:*:*:*:*:*:*:* |
| – | oracle | communications_instant_messaging_server |
10.0.1.5.0 cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.5.0:*:*:*:*:*:*:* |
| – | oracle | communications_messaging_server |
8.1 cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:* |
| – | oracle | communications_network_integrity |
7.3.6 cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:* |
| – | oracle | communications_offline_mediation_controller |
< 12.0.0.4.4 12.0.0.5.0 cpe:2.3:a:oracle:communications_offline_mediation_controller:*:*:*:*:*:*:*:* |
| – | oracle | communications_unified_inventory_management |
7.4.1 7.4.2 cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:* |
| – | oracle | e-business_suite_cloud_manager_and_cloud_backup_module |
< 2.2.1.1.1 2.2.1.1.1 cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:*:*:*:*:*:*:*:* |
| – | oracle | e-business_suite_information_discovery |
>= 12.2.3, <= 12.2.11 cpe:2.3:a:oracle:e-business_suite_information_discovery:*:*:*:*:*:*:*:* |
| – | oracle | enterprise_manager_base_platform |
13.4.0.0 13.5.0.0 cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:* |
| – | oracle | financial_services_revenue_management_and_billing_analytics |
2.7.0.0 2.7.0.1 2.8.0.0 cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.0:*:*:*:*:*:*:* |
| – | oracle | healthcare_foundation |
8.1.0 cpe:2.3:a:oracle:healthcare_foundation:8.1.0:*:*:*:*:*:*:* |
| – | oracle | hyperion_data_relationship_management |
< 11.2.8.0 cpe:2.3:a:oracle:hyperion_data_relationship_management:*:*:*:*:*:*:*:* |
| – | oracle | hyperion_infrastructure_technology |
< 11.2.8.0 cpe:2.3:a:oracle:hyperion_infrastructure_technology:*:*:*:*:*:*:*:* |
| – | oracle | identity_management_suite |
12.2.1.3.0 12.2.1.4.0 cpe:2.3:a:oracle:identity_management_suite:12.2.1.3.0:*:*:*:*:*:*:* |
| – | oracle | identity_manager_connector |
11.1.1.5.0 cpe:2.3:a:oracle:identity_manager_connector:11.1.1.5.0:*:*:*:*:*:*:* |
| – | oracle | jdeveloper |
12.2.1.3.0 cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:* |
| – | oracle | middleware_common_libraries_and_tools |
12.2.1.4.0 cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:* |
| – | oracle | mysql_enterprise_monitor |
<= 8.0.29 cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* |
| – | oracle | retail_extract_transform_and_load |
13.2.5 cpe:2.3:a:oracle:retail_extract_transform_and_load:13.2.5:*:*:*:*:*:*:* |
| – | oracle | tuxedo |
12.2.2.0.0 cpe:2.3:a:oracle:tuxedo:12.2.2.0.0:*:*:*:*:*:*:* |
| – | oracle | weblogic_server |
12.2.1.3.0 12.2.1.4.0 14.1.1.0.0 cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* |
| Root:Maven | root | io.root.log4j:log4j |
< 1.2.12-root.io.1 Fix: upgrade to 1.2.12-root.io.1
|
| Root:Maven | – | log4j:log4j |
< 1.2.14-aikido.4 < 1.2.14-aikido.5 Fix: upgrade to 1.2.14-aikido.4
|
| Root:Maven | – | io.root.log4j:log4j |
< 1.2.14-root.io.4 < 1.2.14-root.io.5 Fix: upgrade to 1.2.14-root.io.4
|
Original advisory text
CVE-2022-23305 in log4j:log4j - Patched by Root
Root has patched CVE-2022-23305 in the log4j:log4j package for Root:Maven. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-23305
- https://github.com/advisories/GHSA-65fg-84f6-3jq3
- https://security.netapp.com/advisory/ntap-20220217-0007
- https://www.oracle.com/security-alerts/cpujul2022.html Patch Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/01/18/4 Mailing List Third Party Advisory
- https://lists.apache.org/thread/pt6lh3pbsvxqlwlp4c5l798dv2hkc85y Issue Tracking Mailing List Vendor Advisory
- https://logging.apache.org/log4j/1.2/index.html Vendor Advisory
- https://security.netapp.com/advisory/ntap-20220217-0007/ Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-89SQL Injection
Timeline
Published1 Oct 2026
Updated1 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta