imPC@ndo IT

Tracker / CVE-2022-23307

CVE-2022-23307

High 8.8

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

Affected products and versions

apache chainsaw · … → 2.1.0
apache log4j · 1.2 → 2.0
oracle advanced_supply_chain_planning
oracle business_intelligence
oracle business_process_management_suite
oracle communications_eagle_ftp_table_base_retrieval
oracle communications_instant_messaging_server
oracle communications_messaging_server
oracle communications_network_integrity
oracle communications_offline_mediation_controller
oracle communications_offline_mediation_controller · … → 12.0.0.4.4
oracle communications_unified_inventory_management
oracle e-business_suite_cloud_manager_and_cloud_backup_module
oracle e-business_suite_cloud_manager_and_cloud_backup_module · … → 2.2.1.1.1
oracle enterprise_manager_base_platform
oracle financial_services_revenue_management_and_billing_analytics
oracle healthcare_foundation
oracle hyperion_data_relationship_management · … → 11.2.8.0
oracle hyperion_infrastructure_technology · … → 11.2.8.0
oracle identity_management_suite
oracle identity_manager_connector
oracle jdeveloper
oracle middleware_common_libraries_and_tools
oracle mysql_enterprise_monitor · … → 8.0.29
oracle retail_extract_transform_and_load
oracle tuxedo
oracle weblogic_server
qos reload4j · … → 1.2.18.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References