CVE-2019-17571: Critical severity Apache Log4j vulnerability

Published Dec 20, 2019
·
Updated

A flaw was discovered in Log4j, where a vulnerable SocketServer class may lead to the deserialization of untrusted data. This flaw allows an attacker to remotely execute arbitrary code when combined with a deserialization gadget.

Other sources

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data.

References:

https://logging.apache.org/log4j/1.2/ https://issues.apache.org/jira/browse/LOG4J2-1863 https://lists.apache.org/thread.html/84cc4266238e057b95eb95dfd8b29d46a2592e7672c12c92f68b2917%40%3Cannounce.apache.org%3E

Red Hat

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions 1.2 up to 1.2.17.

Users are advised to migrate to org.apache.logging.log4j:log4j-core.

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

Affected Software

50 affected componentsFixes available
maven/org.zenframework.z8.dependencies.commons:log4j-1.2.17=2.0
maven/log4j:log4j>=1.2<=1.2.17
debian/apache-log4j1.2<=1.2.17-5, <=1.2.17-7, <=1.2.17-8
1.2.17-91.2.17-8+deb10u11.2.17-7+deb9u1
redhat/log4j<0:1.2.14-6.7.el6_10
0:1.2.14-6.7.el6_10
redhat/log4j<0:1.2.17-16.el7_4
0:1.2.17-16.el7_4
redhat/log4j<0:1.2.14-19.patch_01.ep5.el5
0:1.2.14-19.patch_01.ep5.el5
redhat/log4j<0:1.2.14-19.patch_01.ep5.el6
0:1.2.14-19.patch_01.ep5.el6
redhat/jboss-ec2-eap<0:7.5.17-1.Final_redhat_4.ep6.el6
0:7.5.17-1.Final_redhat_4.ep6.el6
redhat/eap7-jboss-ec2-eap<0:7.0.8-1.GA_redhat_1.ep7.el6
0:7.0.8-1.GA_redhat_1.ep7.el6
redhat/eap7-jboss-ec2-eap<0:7.0.8-1.GA_redhat_1.ep7.el7
0:7.0.8-1.GA_redhat_1.ep7.el7
redhat/log4j-eap6<0:1.2.16-12.redhat_3.1.ep6.el6
0:1.2.16-12.redhat_3.1.ep6.el6
redhat/tomcat7<0:7.0.70-22.ep7.el6
0:7.0.70-22.ep7.el6
redhat/tomcat8<0:8.0.36-24.ep7.el6
0:8.0.36-24.ep7.el6
redhat/tomcat-native<0:1.2.8-10.redhat_10.ep7.el6
0:1.2.8-10.redhat_10.ep7.el6
redhat/log4j-eap6<0:1.2.16-12.redhat_3.1.ep6.el7
0:1.2.16-12.redhat_3.1.ep6.el7
redhat/tomcat7<0:7.0.70-22.ep7.el7
0:7.0.70-22.ep7.el7
redhat/tomcat8<0:8.0.36-24.ep7.el7
0:8.0.36-24.ep7.el7
redhat/tomcat-native<0:1.2.8-10.redhat_10.ep7.el7
0:1.2.8-10.redhat_10.ep7.el7
debian/apache-log4j1.2
1.2.17-10+deb11u11.2.17-11
Apache Log4j<=1.2.17
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Canonical Ubuntu Linux=18.04
openSUSE Leap=15.1
NetApp OnCommand System Manager>=3.0<=3.1.3
NetApp OnCommand Workflow Automation
Oracle Application Testing Suite=13.3.0.1
Oracle Communications Network Integrity>=7.3.2<=7.3.6
Oracle Endeca Information Discovery Studio=3.2.0
Oracle Financial Services Lending And Leasing>=14.1.0<=14.8.0
Oracle Financial Services Lending And Leasing=12.5.0
Oracle MySQL Enterprise Monitor<=8.0.29
Oracle Primavera Gateway>=16.2<=16.2.11
Oracle Primavera Gateway>=17.12.0<=17.12.7
Oracle Rapid Planning=12.1
Oracle Rapid Planning=12.2
Oracle Retail Extract Transform And Load=19.0
Oracle Retail Service Backbone=14.1
Oracle Retail Service Backbone=15.0
Oracle Retail Service Backbone=16.0
Oracle WebLogic Server=10.3.6.0.0
Oracle WebLogic Server=12.1.3.0.0
Oracle WebLogic Server=12.2.1.3.0
Oracle WebLogic Server=12.2.1.4.0
Oracle WebLogic Server=14.1.1.0.0
Apache Bookkeeper<4.14.3
redhat/log4j<2.8.2
2.8.2
IBM Engineering Requirements Management DOORS and DOORS Web Access<=9.7.2.1 - 9.7.2.11
IBM Engineering Requirements Management DOORS and DOORS Web Access<=9.6.1.1 - 9.6.1.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/apache-log4j1.2 to a version that resolves this vulnerability.

    Fixed in 1.2.17-9Fixed in 1.2.17-8+deb10u1Fixed in 1.2.17-7+deb9u1
  2. Upgrade

    Upgrade redhat/log4j to a version that resolves this vulnerability.

    Fixed in 0:1.2.14-6.7.el6_10
  3. Upgrade

    Upgrade redhat/log4j to a version that resolves this vulnerability.

    Fixed in 0:1.2.17-16.el7_4
  4. Upgrade

    Upgrade redhat/log4j to a version that resolves this vulnerability.

    Fixed in 0:1.2.14-19.patch_01.ep5.el5
  5. Upgrade

    Upgrade redhat/log4j to a version that resolves this vulnerability.

    Fixed in 0:1.2.14-19.patch_01.ep5.el6
  6. Upgrade

    Upgrade redhat/jboss-ec2-eap to a version that resolves this vulnerability.

    Fixed in 0:7.5.17-1.Final_redhat_4.ep6.el6
  7. Upgrade

    Upgrade redhat/eap7-jboss-ec2-eap to a version that resolves this vulnerability.

    Fixed in 0:7.0.8-1.GA_redhat_1.ep7.el6
  8. Upgrade

    Upgrade redhat/eap7-jboss-ec2-eap to a version that resolves this vulnerability.

    Fixed in 0:7.0.8-1.GA_redhat_1.ep7.el7
  9. Upgrade

    Upgrade redhat/log4j-eap6 to a version that resolves this vulnerability.

    Fixed in 0:1.2.16-12.redhat_3.1.ep6.el6
  10. Upgrade

    Upgrade redhat/tomcat7 to a version that resolves this vulnerability.

    Fixed in 0:7.0.70-22.ep7.el6
  11. Upgrade

    Upgrade redhat/tomcat8 to a version that resolves this vulnerability.

    Fixed in 0:8.0.36-24.ep7.el6
  12. Upgrade

    Upgrade redhat/tomcat-native to a version that resolves this vulnerability.

    Fixed in 0:1.2.8-10.redhat_10.ep7.el6
  13. Upgrade

    Upgrade redhat/log4j-eap6 to a version that resolves this vulnerability.

    Fixed in 0:1.2.16-12.redhat_3.1.ep6.el7
  14. Upgrade

    Upgrade redhat/tomcat7 to a version that resolves this vulnerability.

    Fixed in 0:7.0.70-22.ep7.el7
  15. Upgrade

    Upgrade redhat/tomcat8 to a version that resolves this vulnerability.

    Fixed in 0:8.0.36-24.ep7.el7
  16. Upgrade

    Upgrade redhat/tomcat-native to a version that resolves this vulnerability.

    Fixed in 0:1.2.8-10.redhat_10.ep7.el7
  17. Upgrade

    Upgrade debian/apache-log4j1.2 to a version that resolves this vulnerability.

    Fixed in 1.2.17-10+deb11u1Fixed in 1.2.17-11
  18. Upgrade

    Upgrade redhat/log4j to a version that resolves this vulnerability.

    Fixed in 2.8.2
  19. Configuration

    If you must continue using SocketAppenders, modify the SocketAppender layout from SerializedLayout to JsonLayout (e.g., set log4j.appender.socket.layout to org.apache.log4j.JsonLayout) to avoid the vulnerable serialized deserialization of untrusted data (Log4j 1.2 up to 1.2.17).

    Log4j 1.2 SocketAppender log4j.appender.socket.layout = org.apache.log4j.JsonLayout
  20. Configuration

    Mitigate by removing the SocketServer class outright (Log4j 1.2 up to 1.2.17), since the included vulnerable SocketServer may lead to deserialization of untrusted data.

    Log4j 1.2 SocketServer class SocketServer usage = removed
  21. Compensating control

    When the application is listening to untrusted network traffic for log data, avoid using the vulnerable SocketServer/SocketAppender configuration that can deserialize untrusted data (Log4j 1.2 up to 1.2.17).

Event History

Dec 20, 2019
CVE Published
12:00 AM
Data Sourced
via Red Hat·01:12 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 6, 2020
Advisory Published
06:43 PM
May 29, 2026
Data Sourced
via Ubuntu·06:54 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·06:54 PM
Description
Jul 6, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2019-17571?

CVE-2019-17571 is a vulnerability in Log4j where a vulnerable SocketServer class may lead to the deserialization of untrusted data, allowing remote code execution.

2

What is the severity of CVE-2019-17571?

CVE-2019-17571 has a severity value of 9, which is considered critical.

3

How does CVE-2019-17571 affect Log4j?

CVE-2019-17571 affects Log4j versions up to 1.2, allowing for remote code execution.

4

What is the recommended remedy for CVE-2019-17571?

The recommended remedy for CVE-2019-17571 is to update Log4j to version 1.2.14-6.7.el6_10 or higher.

5

Where can I find more information about CVE-2019-17571?

You can find more information about CVE-2019-17571 at the following sources: [CVE](https://www.cve.org/CVERecord?id=CVE-2019-17571), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-17571), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1785616), [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2022:5053).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203