Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-05785
HistoryJan 20, 2022 - 12:00 a.m.

Apache log4j Chainsaw deserialization code execution vulnerability

2022-01-2000:00:00
China National Vulnerability Database
www.cnvd.org.cn
19

0.008 Low

EPSS

Percentile

82.3%

Apache Log4j is a Java-based open source logging tool from the Apache Foundation. Apache log4j Chainsaw is vulnerable to deserialized code execution. The vulnerability stems from insufficient cleanup of user-supplied data in JDBCAppender in a non-default configuration with JDBCAppender enabled. A remote attacker could use the vulnerability to send a specially crafted request to the affected application and execute arbitrary SQL commands in the application database.

CPENameOperatorVersion
apache chainsaw <eq2.1.0