CVE-2017-5645

CRITICAL NUCLEI

Apache Log4j 2.0-2.8.1 - Remote Code Execution via Untrusted Data Deserialization

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2017-5645. PoCs published by pimps, HynekPetrak, The-Real-TechLord. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains only a README file describing CVE-2017-5645, an Apache Log4j RCE vulnerability due to insecure deserialization. No actual exploit code or proof-of-concept is present.

Description

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

Exploits (3)

nomisec WRITEUP 92 stars
by pimps · poc
https://github.com/pimps/CVE-2017-5645

This repository contains only a README file describing CVE-2017-5645, an Apache Log4j RCE vulnerability due to insecure deserialization. No actual exploit code or proof-of-concept is present.

Classification
Writeup 90%
Attack Type
Deserialization
Complexity
Theoretical
Reliability
Theoretical
Target: Apache Log4j
No auth needed
Prerequisites: Vulnerable version of Apache Log4j
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 39 stars
by HynekPetrak · poc
https://github.com/HynekPetrak/log4shell-finder

This repository contains a Python-based file system scanner for detecting vulnerable log4j instances, including CVE-2017-5645. It identifies log4j (1.x), reload4j (1.2.18+), and log4j-core (2.x) versions vulnerable to multiple CVEs.

Classification
Scanner 100%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: log4j (1.x), reload4j (1.2.18+), log4j-core (2.x)
No auth needed
Prerequisites: Access to the file system to scan
devstral-2 · analyzed Feb 16, 2026 Full analysis →
gitlab STUB
by The-Real-TechLord · poc
https://gitlab.com/The-Real-TechLord/CVE-2017-5645

The repository contains only a minimal README with a CVE title and description, lacking any exploit code, technical details, or proof-of-concept implementation.

Classification
Stub 90%
Attack Type
Deserialization
Complexity
Theoretical
Reliability
Theoretical
Target: Apache Log4j
No auth needed
devstral-2 · analyzed Feb 23, 2026 Full analysis →

Nuclei Templates (1)

Apache Log4j Server - Deserialization Command Execution
CRITICALby princechaddha

References (82)

Core 82
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2888
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2809
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97702
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041294
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2810
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1801
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2889
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2635
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2638
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1417
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2423
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2808
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040200
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2636
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3399
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2637
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3244
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3400
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2633
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2811
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1802
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1545
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/12/19/2
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Patch, Third Party Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2020.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20181107-0002/
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180726-0002/
Issue Tracking, Vendor Advisory x_refsource_confirm
https://issues.apache.org/jira/browse/LOG4J2-1863
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2020.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2021.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html

Scores

CVSS v3 9.8
EPSS 0.9392
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (50)
apache/log4j 2.0 - 2.8.2
Apache Software Foundation/Apache Log4j All versions between 2.0-alpha1 and 2.8.1
netapp/oncommand_api_services
netapp/oncommand_insight
netapp/oncommand_workflow_automation
netapp/service_level_manager
netapp/snapcenter
netapp/storage_automation_store
oracle/api_gateway 11.1.2.4.0
oracle/application_testing_suite 13.3.0.1
... and 40 more
Published Apr 17, 2017
Tracked Since Feb 18, 2026