Уязвимость CVE-2017-5645: Информация

Описание

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

Важность: CRITICAL (9,8) Вектор: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Опубликовано: 18 апреля 2017 г.
Изменено: 7 ноября 2023 г.
Идентификатор типа ошибки: CWE-502

Ссылки на рекомендации, решения и инструменты

Ссылка
Ресурс
https://issues.apache.org/jira/browse/LOG4J2-1863
  • Issue Tracking
  • Vendor Advisory
97702
  • Third Party Advisory
  • VDB Entry
RHSA-2017:3244
  • Third Party Advisory
RHSA-2017:2889
  • Third Party Advisory
RHSA-2017:2888
  • Third Party Advisory
RHSA-2017:2811
  • Third Party Advisory
RHSA-2017:2810
  • Third Party Advisory
RHSA-2017:2809
  • Third Party Advisory
RHSA-2017:2808
  • Third Party Advisory
RHSA-2017:3400
  • Third Party Advisory
RHSA-2017:3399
  • Third Party Advisory
RHSA-2017:2638
  • Third Party Advisory
RHSA-2017:2637
  • Third Party Advisory
RHSA-2017:2636
  • Third Party Advisory
RHSA-2017:2635
  • Third Party Advisory
RHSA-2017:2633
  • Third Party Advisory
RHSA-2017:2423
  • Third Party Advisory
RHSA-2017:1802
  • Third Party Advisory
RHSA-2017:1801
  • Third Party Advisory
RHSA-2017:1417
  • Third Party Advisory
1040200
  • Third Party Advisory
  • VDB Entry
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
  • Patch
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
  • Patch
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
  • Patch
https://security.netapp.com/advisory/ntap-20180726-0002/
  • Third Party Advisory
1041294
  • Third Party Advisory
  • VDB Entry
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
  • Patch
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20181107-0002/
  • Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
  • Patch
  • Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
  • Patch
  • Third Party Advisory
RHSA-2019:1545
  • Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
  • Patch
  • Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
  • Patch
  • Third Party Advisory
[oss-security] 20191218 [CVE-2019-17571] Apache Log4j 1.2 deserialization of untrusted data in SocketServer
  • Mailing List
  • Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html
  • Third Party Advisory
N/A
  • Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
  • Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
  • Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html
  • Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
  • Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
  • Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
  • Third Party Advisory
[druid-commits] 20191115 [GitHub] [incubator-druid] ccaominh opened a new pull request #8878: Address security vulnerabilities
    [logging-dev] 20191215 Re: Is there any chance that there will be a security fix for log4j-v1.2.17?
      [logging-dev] 20191218 [CVE-2019-17571] Apache Log4j 1.2 deserialization of untrusted data in SocketServer
        [announce] 20191218 [CVE-2019-17571] Apache Log4j 1.2 deserialization of untrusted data in SocketServer
          [logging-dev] 20191219 Re: [CVE-2019-17571] Apache Log4j 1.2 deserialization of untrusted data in SocketServer
            [activemq-issues] 20191226 [jira] [Created] (AMQ-7370) log4j 1.2 version used by AMQ 5.15.10 / 5.15.11 is vulnerable to CVE-2019-17571
              [tika-dev] 20191226 [jira] [Created] (TIKA-3018) log4j 1.2 version used by Apache Tika 1.23 is vulnerable to CVE-2019-17571
                [tika-dev] 20191226 [jira] [Commented] (TIKA-3018) log4j 1.2 version used by Apache Tika 1.23 is vulnerable to CVE-2019-17571
                  [tika-dev] 20191230 [jira] [Created] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]
                    [activemq-issues] 20191230 [jira] [Created] (AMQ-7372) [9.8] [CVE-2019-17571] [activemq-all] [5.15.10]
                      [tika-dev] 20200106 [jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]
                        [tika-dev] 20200107 [jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]
                          [tika-dev] 20200108 [jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]
                            [tika-dev] 20200110 [jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]
                              [tika-dev] 20200111 Re: [jira] [Commented] (TIKA-3018) log4j 1.2 version used by Apache Tika 1.23 is vulnerable to CVE-2019-17571
                                [tika-dev] 20200111 [jira] [Closed] (TIKA-3018) log4j 1.2 version used by Apache Tika 1.23 is vulnerable to CVE-2019-17571
                                  [tika-dev] 20200111 [jira] [Resolved] (TIKA-3018) log4j 1.2 version used by Apache Tika 1.23 is vulnerable to CVE-2019-17571
                                    [tika-dev] 20200114 [jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]
                                      [tika-dev] 20200115 [jira] [Commented] (TIKA-3019) [9.8] [CVE-2019-17571] [tika-app] [1.23]
                                        [activemq-issues] 20200122 [jira] [Updated] (AMQ-7370) log4j 1.2 version used by AMQ 5.15.10 / 5.15.11 is vulnerable to CVE-2019-17571
                                          [activemq-issues] 20200122 [jira] [Assigned] (AMQ-7372) [9.8] [CVE-2019-17571] [activemq-all] [5.15.10]
                                            [activemq-issues] 20200122 [jira] [Updated] (AMQ-7372) [9.8] [CVE-2019-17571] [activemq-all] [5.15.10]
                                              [activemq-issues] 20200122 [jira] [Assigned] (AMQ-7370) log4j 1.2 version used by AMQ 5.15.10 / 5.15.11 is vulnerable to CVE-2019-17571
                                                [activemq-issues] 20200122 [jira] [Resolved] (AMQ-7372) [9.8] [CVE-2019-17571] [activemq-all] [5.15.10]
                                                  [activemq-issues] 20200127 [jira] [Commented] (AMQ-7370) log4j 1.2 version used by AMQ 5.15.10 / 5.15.11 is vulnerable to CVE-2019-17571
                                                    [activemq-issues] 20200208 [jira] [Commented] (AMQ-7370) log4j 1.2 version used by AMQ 5.15.10 / 5.15.11 is vulnerable to CVE-2019-17571
                                                      [activemq-issues] 20200228 [jira] [Commented] (AMQ-7370) log4j 1.2 version used by AMQ 5.15.10 / 5.15.11 is vulnerable to CVE-2019-17571
                                                        [activemq-issues] 20200228 [jira] [Resolved] (AMQ-7370) log4j 1.2 version used by AMQ 5.15.10 / 5.15.11 is vulnerable to CVE-2019-17571
                                                          [activemq-issues] 20200228 [jira] [Updated] (AMQ-7370) log4j 1.2 version used by AMQ 5.15.10 / 5.15.11 is vulnerable to CVE-2019-17571
                                                            [logging-commits] 20200425 svn commit: r1059809 - /websites/production/logging/content/log4j/2.13.2/security.html
                                                              [bookkeeper-issues] 20200729 [GitHub] [bookkeeper] padma81 opened a new issue #2387: Security vulnerabilities in the apache/bookkeeper-4.9.2 image
                                                                [activemq-issues] 20200730 [jira] [Commented] (AMQ-7370) log4j 1.2 version used by AMQ 5.15.10 / 5.15.11 is vulnerable to CVE-2019-17571
                                                                  [geode-issues] 20200831 [jira] [Created] (GEODE-8471) Dependency security issues in geode-core-1.12
                                                                    [doris-commits] 20210402 [GitHub] [incubator-doris] zh0122 opened a new pull request #5594: [FE][Bug]Update log4j-web to fix a security issue
                                                                      [beam-issues] 20210528 [jira] [Created] (BEAM-12422) Vendored gRPC 1.36.0 is using a log4j version with security issues
                                                                        [beam-github] 20210701 [GitHub] [beam] lukecwik commented on pull request #15113: [BEAM-12422] Upgrade log4j version not affected by CVE-2017-5645
                                                                          [beam-github] 20210701 [GitHub] [beam] lukecwik opened a new pull request #15113: [BEAM-12422] Upgrade log4j version not affected by CVE-2017-5645
                                                                            [beam-github] 20210701 [GitHub] [beam] codecov[bot] commented on pull request #15113: [BEAM-12422] Upgrade log4j version not affected by CVE-2017-5645
                                                                              [beam-github] 20210701 [GitHub] [beam] codecov[bot] edited a comment on pull request #15113: [BEAM-12422] Upgrade log4j version not affected by CVE-2017-5645
                                                                                [beam-github] 20210701 [GitHub] [beam] suztomo commented on pull request #15113: [BEAM-12422] Upgrade log4j version not affected by CVE-2017-5645
                                                                                    1. Конфигурация 1

                                                                                      cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      2.0
                                                                                      End excliding
                                                                                      2.8.2

                                                                                      Конфигурация 2

                                                                                      cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:netapp:service_level_manager:-:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:netapp:oncommand_api_services:-:*:*:*:*:*:*:*

                                                                                      Конфигурация 3

                                                                                      cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux:7.4:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux:7.5:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux_server_tus:7.4:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*

                                                                                      cpe:2.3:o:redhat:enterprise_linux:7.6:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:*

                                                                                      Конфигурация 4

                                                                                      cpe:2.3:a:oracle:flexcube_investor_servicing:12.3.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:flexcube_investor_servicing:12.1.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_service_backbone:14.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:enterprise_manager_base_platform:12.1.0.5:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:api_gateway:11.1.2.4.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:flexcube_investor_servicing:12.0.4:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_service_backbone:15.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:jdeveloper:12.1.3.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_integration_bus:15.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:flexcube_investor_servicing:12.4.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:soa_suite:12.1.3.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:soa_suite:12.2.1.3.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:identity_analytics:11.1.1.5.8:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:siebel_ui_framework:18.7:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:siebel_ui_framework:18.8:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:siebel_ui_framework:18.9:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_open_commerce_platform:6.0.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:flexcube_investor_servicing:14.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:insurance_rules_palette:10.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:insurance_rules_palette:10.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:tape_library_acsls:8.4:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_open_commerce_platform:5.3.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_open_commerce_platform:6.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:insurance_calculation_engine:10.2.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:insurance_calculation_engine:10.1.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:insurance_rules_palette:10.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:insurance_rules_palette:11.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:insurance_rules_palette:11.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_integration_bus:16.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:banking_platform:2.6.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:banking_platform:2.6.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:communications_webrtc_session_controller:*:*:*:*:*:*:*:*
                                                                                      End excliding
                                                                                      7.2

                                                                                      cpe:2.3:a:oracle:enterprise_manager_for_peoplesoft:13.1.1.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:enterprise_manager_for_peoplesoft:13.2.1.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:enterprise_manager_for_oracle_database:12.1.0.8:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:enterprise_manager_for_oracle_database:13.2.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:enterprise_manager_for_mysql_database:*:*:*:*:*:*:*:*
                                                                                      End including
                                                                                      13.2.2.0.0

                                                                                      cpe:2.3:a:oracle:enterprise_manager_for_fusion_middleware:12.1.0.5:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:enterprise_manager_for_fusion_middleware:13.2.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:communications_pricing_design_center:11.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:communications_pricing_design_center:12.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:communications_converged_application_server_-_service_controller:6.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:communications_online_mediation_controller:6.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:communications_service_broker:6.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:goldengate_application_adapters:12.3.2.1.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:soa_suite:12.2.2.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:communications_messaging_server:*:*:*:*:*:*:*:*
                                                                                      End excliding
                                                                                      8.0.2

                                                                                      cpe:2.3:a:oracle:configuration_manager:12.1.2.0.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:configuration_manager:12.1.2.0.5:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:bi_publisher:11.1.1.7.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:bi_publisher:11.1.1.9.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:bi_publisher:12.2.1.3.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:identity_management_suite:11.1.2.3.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:identity_management_suite:12.2.1.3.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_extract_transform_and_load:13.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_extract_transform_and_load:13.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_extract_transform_and_load:13.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:utilities_work_and_asset_management:1.9.1.2.12:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:autovue_vuelink_integration:21.0.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:autovue_vuelink_integration:21.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_integration_bus:14.1.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_integration_bus:14.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_clearance_optimization_engine:14.0.5:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:10.4.7:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.1.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.1.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.2.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.2.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.2.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.2.3:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.2.4:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.2.5:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.2.6:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.2.7:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.2.8:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.2.9:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_for_mobile_devices:12.2.10:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation_connector_for_siebel:10.4.6:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:10.4.7:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.1.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.1.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.2.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.2.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.2.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.2.3:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.2.4:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.2.5:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.2.6:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.2.7:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.2.8:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.2.9:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:policy_automation:12.2.10:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:peoplesoft_enterprise_fin_install:9.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      8.0.0.0.0
                                                                                      End including
                                                                                      8.0.0.8131

                                                                                      cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      4.0.0.0
                                                                                      End including
                                                                                      4.0.4.5235

                                                                                      cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      3.4.0.0
                                                                                      End including
                                                                                      3.4.7.4297

                                                                                      cpe:2.3:a:oracle:insurance_policy_administration:10.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:insurance_policy_administration:10.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:insurance_policy_administration:10.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:insurance_policy_administration:11.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.3:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:enterprise_data_quality:12.2.1.3.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:financial_services_profitability_management:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      8.0.0.0.0
                                                                                      End including
                                                                                      8.0.7.0.0

                                                                                      cpe:2.3:a:oracle:financial_services_profitability_management:6.1.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:8.0.4:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:financial_services_loan_loss_forecasting_and_provisioning:8.0.5:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:8.0.4:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:financial_services_hedge_management_and_ifrs_valuations:8.0.5:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:financial_services_behavior_detection_platform:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      8.0.0.0.0
                                                                                      End including
                                                                                      8.0.4.0.0

                                                                                      cpe:2.3:a:oracle:financial_services_behavior_detection_platform:6.1.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      8.0.0.0.0
                                                                                      End including
                                                                                      8.0.7.0.0

                                                                                      cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      7.3.3.0.0
                                                                                      End including
                                                                                      7.3.3.0.2

                                                                                      cpe:2.3:a:oracle:endeca_information_discovery_studio:3.2.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:rapid_planning:12.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:rapid_planning:12.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:instantis_enterprisetrack:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      17.1
                                                                                      End including
                                                                                      17.3

                                                                                      cpe:2.3:a:oracle:utilities_advanced_spatial_and_operational_analytics:2.7.0.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      16.2.0
                                                                                      End including
                                                                                      16.2.11

                                                                                      cpe:2.3:a:oracle:identity_manager_connector:9.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:financial_services_lending_and_leasing:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      14.1.0
                                                                                      End including
                                                                                      14.8.0

                                                                                      cpe:2.3:a:oracle:financial_services_lending_and_leasing:12.5.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:communications_network_integrity:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      7.3.2
                                                                                      End including
                                                                                      7.3.6

                                                                                      cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      17.12.0
                                                                                      End including
                                                                                      17.12.7

                                                                                      cpe:2.3:a:oracle:retail_service_backbone:16.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_extract_transform_and_load:19.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.3.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:financial_services_regulatory_reporting_with_agilereporter:8.0.9.2.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_advanced_inventory_planning:15.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:timesten_in-memory_database:11.2.2.8.49:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:communications_interactive_session_recorder:*:*:*:*:*:*:*:*
                                                                                      Start including
                                                                                      6.0
                                                                                      End including
                                                                                      6.2

                                                                                      cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:4.0.1.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:in-memory_performance-driven_planning:12.2:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:in-memory_performance-driven_planning:12.1:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:retail_advanced_inventory_planning:14.0:*:*:*:*:*:*:*

                                                                                      cpe:2.3:a:oracle:goldengate:12.3.2.1.1:*:*:*:*:*:*:*