CVE-2022-23305

Description

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
7.951

Associated Vulnerability

VulnerabilityOS Platform
Log4j Vulnerability (CVE-2022-23305,CVE-2021-4104)Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.3.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.4.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 14.1.1.0.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.3.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.4.0Windows
Vulnerabilities CVE-2021-44832,CVE-2022-23305 are fixed in Oracle Hyperion Data Relationship Management 11.2.8.0Windows
Vulnerabilities CVE-2020-2730,CVE-2022-23305 are affected in Oracle Financial Services Revenue Management and Billing 2.7.0.0Windows
Vulnerabilities CVE-2020-2730,CVE-2022-23305 are affected in Oracle Financial Services Revenue Management and Billing 2.7.0.1Windows
Vulnerabilities CVE-2020-2730,CVE-2022-23305 are affected in Oracle Financial Services Revenue Management and Billing 2.8.0.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.2Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.3Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.4Windows
Vulnerabilities CVE-2019-10072,CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.3.2Windows
Multiple Vulnerabilities are affected in IBM App Connect Enterprise 11.0.0.15Windows
Multiple Vulnerabilities are affected in IBM App Connect Enterprise 12.0.3.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.9Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.5.4Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.1.1.1Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.5.3Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.1.0.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.1.1.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.1.1.2Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.8Windows
Vulnerabilities CVE-2020-36518,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.2.0.0Windows
Vulnerabilities CVE-2020-36518,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.2.0.1Windows
Vulnerabilities CVE-2020-36518,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.2.0.2Windows
Vulnerabilities CVE-2020-36518,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.2.1.0Windows
Vulnerabilities CVE-2020-36518,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.2.1.1Windows
Vulnerabilities CVE-2020-36518,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.2.1.2Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 6.2.7.10Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 6.2.7.11Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 6.2.7.12Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 6.2.7.5Windows
Vulnerabilities CVE-2020-4260,CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 6.2.7.6Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 6.2.7.7Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.3.1Windows
Vulnerabilities CVE-2020-4202,CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.3.3Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.4.1Windows
Vulnerabilities CVE-2020-4202,CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.4.2Windows
Vulnerabilities CVE-2020-4260,CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.5.0Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.5.1Windows
Vulnerabilities CVE-2019-4667,CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.5.2Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.5.5Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.5.6Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.1.0.1Windows
Vulnerabilities CVE-2021-4104,CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.1.0.2Windows
Multiple Vulnerabilities are affected in IBM App Connect Enterprise 11.0.0.16Windows
Vulnerabilities CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.5.7Windows
Vulnerabilities CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.1.2.1Windows
Vulnerabilities CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.1.2.2Windows
Vulnerabilities CVE-2021-42340,CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.1.2.3Windows
Vulnerabilities CVE-2022-23305 are affected in IBM UrbanCode Deploy 6.2.7.13Windows
Vulnerabilities CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.0.5.8Windows
Vulnerabilities CVE-2022-23305 are affected in IBM UrbanCode Deploy 7.1.2.4Windows
Vulnerabilities CVE-2022-23305,CVE-2022-23307,CVE-2022-23302 are affected in Apache-log4j 1.2.17Windows
Vulnerabilities CVE-2022-23305,CVE-2022-23307,CVE-2021-4104,CVE-2022-23302 are affected in Zenframework - log4j-1.2.17 2.0Windows
(RHSA-2022:0290) parfait:0.5 security update parfait-0.5.4-4.module+el8.5.0+13988+de2b8c0b.noarch.rpmLinux
(RHSA-2022:0290) parfait:0.5 security update parfait-examples-0.5.4-4.module+el8.5.0+13988+de2b8c0b.noarch.rpmLinux
(RHSA-2022:0290) parfait:0.5 security update parfait-javadoc-0.5.4-4.module+el8.5.0+13988+de2b8c0b.noarch.rpmLinux
(RHSA-2022:0290) parfait:0.5 security update pcp-parfait-agent-0.5.4-4.module+el8.5.0+13988+de2b8c0b.noarch.rpmLinux
(RHSA-2022:0290) parfait:0.5 security update si-units-javadoc-0.6.5-2.module+el8+2463+615f6896.noarch.rpmLinux
(RHSA-2022:0290) parfait:0.5 security update unit-api-javadoc-1.0-5.module+el8+2463+615f6896.noarch.rpmLinux
(RHSA-2022:0290) parfait:0.5 security update uom-lib-javadoc-1.0.1-6.module+el8+2463+615f6896.noarch.rpmLinux
(RHSA-2022:0290) parfait:0.5 security update uom-parent-1.0.3-3.module+el8+2463+615f6896.noarch.rpmLinux
(RHSA-2022:0290) parfait:0.5 security update uom-se-javadoc-1.0.4-3.module+el8+2463+615f6896.noarch.rpmLinux
(RHSA-2022:0290) parfait:0.5 security update uom-systems-javadoc-0.7-1.module+el8+2463+615f6896.noarch.rpmLinux
SUSE-SU-2022:0212-1(SUSE Linux Enterprise Server 12-SP5 ) log4j-1.2.15-126.9.1.noarch.rpmLinux
Parfait update (ELSA-2022-0290) parfait-0.5.4-4.module+el8.5.0+20480+407d1823.noarch.rpmLinux
Parfait-examples update (ELSA-2022-0290) parfait-examples-0.5.4-4.module+el8.5.0+20480+407d1823.noarch.rpmLinux
Parfait-javadoc update (ELSA-2022-0290) parfait-javadoc-0.5.4-4.module+el8.5.0+20480+407d1823.noarch.rpmLinux
Pcp-parfait-agent update (ELSA-2022-0290) pcp-parfait-agent-0.5.4-4.module+el8.5.0+20480+407d1823.noarch.rpmLinux
Si-units update (ELSA-2022-0290) si-units-0.6.5-2.module+el8+5163+abb6ece5.noarch.rpmLinux
Si-units-javadoc update (ELSA-2022-0290) si-units-javadoc-0.6.5-2.module+el8+5163+abb6ece5.noarch.rpmLinux
Unit-api update (ELSA-2022-0290) unit-api-1.0-5.module+el8+5163+abb6ece5.noarch.rpmLinux
Unit-api-javadoc update (ELSA-2022-0290) unit-api-javadoc-1.0-5.module+el8+5163+abb6ece5.noarch.rpmLinux
Uom-lib update (ELSA-2022-0290) uom-lib-1.0.1-6.module+el8+5163+abb6ece5.noarch.rpmLinux
Uom-lib-javadoc update (ELSA-2022-0290) uom-lib-javadoc-1.0.1-6.module+el8+5163+abb6ece5.noarch.rpmLinux
Uom-parent update (ELSA-2022-0290) uom-parent-1.0.3-3.module+el8+5163+abb6ece5.noarch.rpmLinux
Uom-se update (ELSA-2022-0290) uom-se-1.0.4-3.module+el8+5163+abb6ece5.noarch.rpmLinux
Uom-se-javadoc update (ELSA-2022-0290) uom-se-javadoc-1.0.4-3.module+el8+5163+abb6ece5.noarch.rpmLinux
Uom-systems update (ELSA-2022-0290) uom-systems-0.7-1.module+el8+5163+abb6ece5.noarch.rpmLinux
Uom-systems-javadoc update (ELSA-2022-0290) uom-systems-javadoc-0.7-1.module+el8+5163+abb6ece5.noarch.rpmLinux
(RHSA-2022:0442) log4j security update log4j-1.2.17-18.el7_4.noarch.rpmLinux
(RHSA-2022:0442) log4j security update log4j-javadoc-1.2.17-18.el7_4.noarch.rpmLinux
(RHSA-2022:0442) log4j security update log4j-manual-1.2.17-18.el7_4.noarch.rpmLinux
Log4j update (ELSA-2022-0442) log4j-1.2.17-18.el7_4.noarch.rpmLinux
Log4j-javadoc update (ELSA-2022-0442) log4j-javadoc-1.2.17-18.el7_4.noarch.rpmLinux
Log4j-manual update (ELSA-2022-0442) log4j-manual-1.2.17-18.el7_4.noarch.rpmLinux
Java-based open-source logging tool (USN-5998-1) liblog4j1.2-java_1.2.17-9ubuntu0.2_all.debLinux
Java-based open-source logging tool (USN-5998-1) liblog4j1.2-java_1.2.17-8+deb10u1ubuntu0.2_all.debLinux
(RHSA-2022:0290)Important: security update si-units-0.6.5-2.module+el8+2463+615f6896.noarch.rpmLinux
(RHSA-2022:0290)Important: security update unit-api-1.0-5.module+el8+2463+615f6896.noarch.rpmLinux
(RHSA-2022:0290)Important: security update uom-lib-1.0.1-6.module+el8+2463+615f6896.noarch.rpmLinux
(RHSA-2022:0290)Important: security update uom-se-1.0.4-3.module+el8+2463+615f6896.noarch.rpmLinux
(RHSA-2022:0290)Important: security update uom-systems-0.7-1.module+el8+2463+615f6896.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) uom-se-1.0.4-3.module+el8.3.0+214+edf13b3f.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) parfait-0.5.4-4.module+el8.5.0+728+553fbdb8.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) uom-lib-1.0.1-6.module+el8.3.0+214+edf13b3f.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) si-units-0.6.5-2.module+el8.3.0+214+edf13b3f.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) unit-api-1.0-5.module+el8.3.0+214+edf13b3f.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) uom-parent-1.0.3-3.module+el8.3.0+214+edf13b3f.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) uom-systems-0.7-1.module+el8.3.0+214+edf13b3f.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) uom-se-javadoc-1.0.4-3.module+el8.3.0+214+edf13b3f.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) parfait-javadoc-0.5.4-4.module+el8.5.0+728+553fbdb8.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) uom-lib-javadoc-1.0.1-6.module+el8.3.0+214+edf13b3f.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) parfait-examples-0.5.4-4.module+el8.5.0+728+553fbdb8.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) si-units-javadoc-0.6.5-2.module+el8.3.0+214+edf13b3f.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) unit-api-javadoc-1.0-5.module+el8.3.0+214+edf13b3f.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) pcp-parfait-agent-0.5.4-4.module+el8.5.0+728+553fbdb8.noarch.rpmLinux
parfait:0.5 security update (RLSA-2022:0290) uom-systems-javadoc-0.7-1.module+el8.3.0+214+edf13b3f.noarch.rpmLinux
log4j Security Update (ALAS-2022-1750) log4j-1.2.17-18.amzn2.noarch.rpmLinux
log4j Security Update (ALAS-2022-1750) log4j-manual-1.2.17-18.amzn2.noarch.rpmLinux
log4j Security Update (ALAS-2022-1750) log4j-javadoc-1.2.17-18.amzn2.noarch.rpmLinux
Important: parfait:0.5 security update unit-api-1.0-5.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update unit-api-javadoc-1.0-5.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update uom-lib-1.0.1-6.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update uom-lib-javadoc-1.0.1-6.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update uom-parent-1.0.3-3.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update uom-se-1.0.4-3.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update uom-se-javadoc-1.0.4-3.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update uom-systems-0.7-1.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update uom-systems-javadoc-0.7-1.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update si-units-0.6.5-2.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update si-units-javadoc-0.6.5-2.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update parfait-0.5.4-4.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update parfait-examples-0.5.4-4.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update parfait-javadoc-0.5.4-4.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Important: parfait:0.5 security update pcp-parfait-agent-0.5.4-4.module_el8.5.0+2610+de2b8c0b.noarch.rpmLinux
Vulnerabilities CVE-2022-23305,CVE-2022-23307,CVE-2022-23302 are affected in Apache-log4j for Linux 1.2.17Linux
Vulnerabilities CVE-2022-23305,CVE-2022-23307,CVE-2021-4104,CVE-2022-23302 are affected in Zenframework - log4j-1.2.17 for Linux 2.0Linux
Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability (CVE-2022-23305)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234