8.8
HIGH
CVE-2022-23302
Apache Log4j JMSSink Remote Code Execution Vulnerability
Description

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

INFO

Published Date :

Jan. 18, 2022, 4:15 p.m.

Last Modified :

Feb. 24, 2023, 3:30 p.m.

Remotely Exploitable :

Yes !

Impact Score :

5.9

Exploitability Score :

2.8
Public PoC/Exploit Available at Github

CVE-2022-23302 has a 14 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2022-23302 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Oracle business_intelligence
2 Oracle weblogic_server
3 Oracle identity_manager_connector
4 Oracle mysql_enterprise_monitor
5 Oracle hyperion_data_relationship_management
6 Oracle tuxedo
7 Oracle business_process_management_suite
8 Oracle communications_instant_messaging_server
9 Oracle communications_offline_mediation_controller
10 Oracle communications_unified_inventory_management
11 Oracle jdeveloper
12 Oracle communications_network_integrity
13 Oracle enterprise_manager_base_platform
14 Oracle communications_messaging_server
15 Oracle healthcare_foundation
16 Oracle hyperion_infrastructure_technology
17 Oracle communications_eagle_ftp_table_base_retrieval
18 Oracle financial_services_revenue_management_and_billing_analytics
19 Oracle middleware_common_libraries_and_tools
20 Oracle identity_management_suite
21 Oracle advanced_supply_chain_planning
22 Oracle e-business_suite_cloud_manager_and_cloud_backup_module
1 Netapp snapmanager
1 Broadcom brocade_sannav
1 Apache log4j
1 Qos reload4j
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2022-23302.

URL Resource
http://www.openwall.com/lists/oss-security/2022/01/18/3 Mailing List Third Party Advisory
https://lists.apache.org/thread/bsr3l5qz4g0myrjhy9h67bcxodpkwj4w Mailing List Mitigation Vendor Advisory
https://logging.apache.org/log4j/1.2/index.html Vendor Advisory
https://security.netapp.com/advisory/ntap-20220217-0006/ Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html Patch Third Party Advisory

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Java Perl HTML C++ CSS Raku Batchfile Roff

Updated: 6 months, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : Feb. 21, 2024, 8:25 a.m. This repo has been linked 7 different CVEs too.

None

Java Perl HTML C++ CSS Batchfile Raku Roff

Updated: 1 year, 7 months ago
0 stars 0 fork 0 watcher
Born at : Jan. 17, 2023, 7:35 a.m. This repo has been linked 7 different CVEs too.

None

Makefile Go

Updated: 1 week, 6 days ago
0 stars 0 fork 0 watcher
Born at : July 10, 2022, 7:28 p.m. This repo has been linked 30 different CVEs too.

None

Java Perl HTML C++ CSS Batchfile Raku Roff

Updated: 2 years, 5 months ago
0 stars 0 fork 0 watcher
Born at : April 10, 2022, 7:54 p.m. This repo has been linked 7 different CVEs too.

None

Updated: 2 years, 2 months ago
1 stars 0 fork 0 watcher
Born at : Feb. 6, 2022, 6:14 p.m. This repo has been linked 9 different CVEs too.

Fork of Log4j 1.2 project, without additional appenders and classes causing security issues.

Java HTML

Updated: 2 years, 7 months ago
1 stars 0 fork 0 watcher
Born at : Jan. 29, 2022, 2:26 p.m. This repo has been linked 6 different CVEs too.

test 反向辣鸡数据投放 CVE-2022-23305 工具 利用 教程 Exploit POC

cve-2020-

Updated: 1 year, 10 months ago
5 stars 2 fork 2 watcher
Born at : Jan. 21, 2022, 5:07 a.m. This repo has been linked 2608 different CVEs too.

CVE-log4j CheckMK plugin

log4j2 checkmk-extension checkmk-agent cve-2021-44228 cve-2021-45046 cve-2021-4104 cve-2021-42550 cve-2021-45105 cve-2021-44832

Python Shell

Updated: 1 year, 2 months ago
5 stars 0 fork 0 watcher
Born at : Jan. 3, 2022, 8:55 p.m. This repo has been linked 12 different CVEs too.

Long Term Support version of a stripped down log4j

Java HTML C++ CSS Batchfile Raku Roff

Updated: 2 years, 8 months ago
2 stars 3 fork 3 watcher
Born at : Dec. 16, 2021, 6:35 a.m. This repo has been linked 7 different CVEs too.

Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.

cve-2021-44228 cve-2021-45046 log4j log4shell vulnerability security scanner log4j2 cve-2021-4104 cve-2021-42550 cve-2021-45105 cve-2021-44832 cve-2017-5645 cve-2019-17571 cve-2022-23305 cve-2022-23307 cve-2022-23302 cve-2020-9488

Python

Updated: 4 months ago
37 stars 13 fork 13 watcher
Born at : Dec. 14, 2021, 10:27 p.m. This repo has been linked 12 different CVEs too.

None

Go Ruby

Updated: 1 month, 1 week ago
138 stars 22 fork 22 watcher
Born at : Dec. 14, 2021, 7:24 a.m. This repo has been linked 10 different CVEs too.

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228

cve-2021-44228 log4j2 scanner patch cve-2021-45046 cve-2021-4104 cve-2021-42550 cve-2021-45105 cve-2021-44832 cve-2022-23302 cve-2022-23305 cve-2022-23307

Java

Updated: 1 week, 1 day ago
855 stars 170 fork 170 watcher
Born at : Dec. 11, 2021, 11:18 a.m. This repo has been linked 12 different CVEs too.

Oracle database CDC (Change Data Capture)

oracle-database oraclegoldengate cdc change-data-capture kafka kafka-connect amazon amazon-web-services aws aws-msk confluent-kafka confluent-platform oracle-rdbms oracle-wallet oracle-golden-gate oracle

Shell Java Dockerfile

Updated: 1 week, 6 days ago
105 stars 36 fork 36 watcher
Born at : Sept. 26, 2019, 9:17 p.m. This repo has been linked 6 different CVEs too.

Apache log4j1

log4j

Java HTML C++ Roff Perl CSS Batchfile Raku

Updated: 3 weeks, 1 day ago
873 stars 561 fork 561 watcher
Born at : May 21, 2009, 1:31 a.m. This repo has been linked 7 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2022-23302 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2022-23302 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • Modified Analysis by [email protected]

    Feb. 24, 2023

    Action Type Old Value New Value
    Changed Reference Type https://www.oracle.com/security-alerts/cpujul2022.html No Types Assigned https://www.oracle.com/security-alerts/cpujul2022.html Patch, Third Party Advisory
    Changed CPE Configuration OR *cpe:2.3:a:oracle:advanced_supply_chain_planning:12.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:advanced_supply_chain_planning:12.2:*:*:*:*:*:*:* *cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:* *cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:* *cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:* *cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2:*:*:*:*:*:*:* *cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:*:*:*:*:*:*:*:* versions up to (excluding) 2.2.1.1.1 *cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:2.2.1.1.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.8.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:healthcare_foundation:8.1.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:hyperion_data_relationship_management:*:*:*:*:*:*:*:* versions up to (excluding) 11.2.8.0 *cpe:2.3:a:oracle:hyperion_infrastructure_technology:*:*:*:*:*:*:*:* versions up to (excluding) 11.2.8.0 *cpe:2.3:a:oracle:identity_management_suite:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:identity_management_suite:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:identity_manager_connector:11.1.1.5.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* versions up to (including) 8.0.29 *cpe:2.3:a:oracle:tuxedo:12.2.2.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* OR *cpe:2.3:a:oracle:advanced_supply_chain_planning:12.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:advanced_supply_chain_planning:12.2:*:*:*:*:*:*:* *cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:* *cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:* *cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:* *cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.5.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_offline_mediation_controller:*:*:*:*:*:*:*:* versions up to (excluding) 12.0.0.4.4 *cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.5.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2:*:*:*:*:*:*:* *cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:*:*:*:*:*:*:*:* versions up to (excluding) 2.2.1.1.1 *cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:2.2.1.1.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.8.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:healthcare_foundation:8.1.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:hyperion_data_relationship_management:*:*:*:*:*:*:*:* versions up to (excluding) 11.2.8.0 *cpe:2.3:a:oracle:hyperion_infrastructure_technology:*:*:*:*:*:*:*:* versions up to (excluding) 11.2.8.0 *cpe:2.3:a:oracle:identity_management_suite:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:identity_management_suite:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:identity_manager_connector:11.1.1.5.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* versions up to (including) 8.0.29 *cpe:2.3:a:oracle:tuxedo:12.2.2.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
  • CVE Modified by [email protected]

    Jul. 25, 2022

    Action Type Old Value New Value
    Added Reference https://www.oracle.com/security-alerts/cpujul2022.html [No Types Assigned]
  • Modified Analysis by [email protected]

    Jun. 16, 2022

    Action Type Old Value New Value
    Changed Reference Type https://www.oracle.com/security-alerts/cpuapr2022.html No Types Assigned https://www.oracle.com/security-alerts/cpuapr2022.html Patch, Third Party Advisory
    Added CPE Configuration OR *cpe:2.3:a:oracle:advanced_supply_chain_planning:12.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:advanced_supply_chain_planning:12.2:*:*:*:*:*:*:* *cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:* *cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:* *cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:* *cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2:*:*:*:*:*:*:* *cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:*:*:*:*:*:*:*:* versions up to (excluding) 2.2.1.1.1 *cpe:2.3:a:oracle:e-business_suite_cloud_manager_and_cloud_backup_module:2.2.1.1.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7.0.1:*:*:*:*:*:*:* *cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.8.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:healthcare_foundation:8.1.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:hyperion_data_relationship_management:*:*:*:*:*:*:*:* versions up to (excluding) 11.2.8.0 *cpe:2.3:a:oracle:hyperion_infrastructure_technology:*:*:*:*:*:*:*:* versions up to (excluding) 11.2.8.0 *cpe:2.3:a:oracle:identity_management_suite:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:identity_management_suite:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:identity_manager_connector:11.1.1.5.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* versions up to (including) 8.0.29 *cpe:2.3:a:oracle:tuxedo:12.2.2.0.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* *cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
  • CVE Modified by [email protected]

    Apr. 20, 2022

    Action Type Old Value New Value
    Added Reference https://www.oracle.com/security-alerts/cpuapr2022.html [No Types Assigned]
  • Reanalysis by [email protected]

    Apr. 08, 2022

    Action Type Old Value New Value
    Added CPE Configuration OR *cpe:2.3:a:qos:reload4j:*:*:*:*:*:*:*:* versions up to (excluding) 1.2.18.1
  • Modified Analysis by [email protected]

    Mar. 04, 2022

    Action Type Old Value New Value
    Changed Reference Type http://www.openwall.com/lists/oss-security/2022/01/18/3 No Types Assigned http://www.openwall.com/lists/oss-security/2022/01/18/3 Mailing List, Third Party Advisory
    Changed Reference Type https://security.netapp.com/advisory/ntap-20220217-0006/ No Types Assigned https://security.netapp.com/advisory/ntap-20220217-0006/ Third Party Advisory
    Added CPE Configuration OR *cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:* *cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:sap:*:*
    Added CPE Configuration OR *cpe:2.3:a:broadcom:brocade_sannav:-:*:*:*:*:*:*:*
  • CVE Modified by [email protected]

    Feb. 17, 2022

    Action Type Old Value New Value
    Added Reference http://www.openwall.com/lists/oss-security/2022/01/18/3 [No Types Assigned]
    Added Reference https://security.netapp.com/advisory/ntap-20220217-0006/ [No Types Assigned]
  • Initial Analysis by [email protected]

    Jan. 27, 2022

    Action Type Old Value New Value
    Added CVSS V2 NIST (AV:N/AC:M/Au:S/C:P/I:P/A:P)
    Added CVSS V3.1 NIST AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Changed Reference Type https://lists.apache.org/thread/bsr3l5qz4g0myrjhy9h67bcxodpkwj4w No Types Assigned https://lists.apache.org/thread/bsr3l5qz4g0myrjhy9h67bcxodpkwj4w Mailing List, Mitigation, Vendor Advisory
    Changed Reference Type https://logging.apache.org/log4j/1.2/index.html No Types Assigned https://logging.apache.org/log4j/1.2/index.html Vendor Advisory
    Added CWE NIST CWE-502
    Added CPE Configuration OR *cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* versions from (including) 1.0.1 up to (including) 1.2.17
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2022-23302 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2022-23302 weaknesses.

Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

0.54 }} -0.07%

score

0.77271

percentile

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability