Where
AND
-Infinity
0

Vendor Risk Score

See how oracle compares to other vendors in security performance

View Risk Score →

Software

oracle communications offline mediation controller
4
oracle vm virtualbox
4
oracle weblogic server
4
oracle advanced supply chain planning
3
oracle business intelligence
3
oracle business process management suite
3
oracle communications eagle ftp table base retrieval
3
oracle communications instant messaging server
3
oracle communications messaging server
3
oracle communications network integrity
3
oracle communications unified inventory management
3
oracle e-business suite cloud manager and cloud backup module
3
oracle enterprise manager base platform
3
oracle financial services revenue management and billing analytics
3
oracle healthcare foundation
3
oracle hyperion data relationship management
3
oracle hyperion infrastructure technology
3
oracle identity management suite
3
oracle identity manager connector
3
oracle jdeveloper
3
oracle middleware common libraries and tools
3
oracle mysql enterprise monitor
3
oracle tuxedo
3
oracle e-business suite
2
oracle retail extract transform and load
2
oracle cloud
1
oracle cloud classic
1
oracle communications brm - elastic charging engine
1
oracle communications diameter signaling router
1
oracle communications interactive session recorder
1
oracle e-business suite information discovery
1
oracle flexcube private banking
1
oracle health
1
oracle health cerner
1
oracle health sciences data management workbench
1
oracle identity manager
1
oracle peoplesoft enterprise applications
1
oracle peoplesoft peopletools
1
oracle policy automation
1
oracle policy automation for mobile devices
1
oracle primavera gateway
1
oracle primavera p6 enterprise project portfolio management
1
oracle primavera unifier
1
oracle product lifecycle analytics
1
oracle retail assortment planning
1
oracle retail fiscal management
1
oracle retail order broker
1
oracle retail xstore point of service
1
oracle siebel ui framework
1
Severity
9.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A deserialization flaw was found in Apache log4j 1.2.x. While reading serialized log events, they are improperly deserialized.

Note this is the same as CVE-2020-9493 which identified a deserialization issue in Apache Chainsaw. Prior to Chainsaw V2.0, Chainsaw was a component of Apache Log4j 1.2.x.

References:

https://www.openwall.com/lists/oss-security/2022/01/18/5

1 / 5
Source: Red Hat
First published (updated )
Severity
9.8
SQL Injection
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A flaw was found in the Java logging library Apache Log4j in version 1.x. JDBCAppender in Log4j 1.x is vulnerable to SQL injection in untrusted data. This allows a remote attacker to run SQL statements in the database if the deployed application is configured to use JDBCAppender with certain interpolation tokens.

1 / 4
First published (updated )
Severity
9.8
Input Validation
AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Apache Log4j <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled (CVE-2021-44228).

1 / 6
Source: FortiGuard

Remedy

As per upstream: - In prior releases confirm that if the JDBC Appender is being used it is not configured to use any protocol other than Java. - Note that only the log4j-core JAR file is impacted by this vulnerability. Applications using only the log4j-api JAR file without the log4j-core JAR file are not impacted by this vulnerability.
First published (updated )
Severity
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A flaw was found in the Java logging library Apache Log4j in version 1.x. JMSSink in Log4j 1.x is vulnerable to deserialization of untrusted data. This allows a remote attacker to execute code on the server if JMSSink is deployed and has been configured to perform JNDI requests.

1 / 4
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203