Revision Date: | 2022-01-28 | Version: | 1 |
Title: | (Important) |
Description: |
This update for log4j12 fixes the following issues:
- CVE-2022-23307: Fix deserialization issue by removing the chainsaw sub-package. (bsc#1194844) - CVE-2022-23305: Fix SQL injection by removing src/main/java/org/apache/log4j/jdbc/JDBCAppender.java. (bsc#1194843) - CVE-2022-23302: Fix remote code execution by removing src/main/java/org/apache/log4j/net/JMSSink.java. (bsc#1194842)
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1193184 1194842 1194843 1194844 CVE-2015-3294 CVE-2015-8899 CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 CVE-2017-15107 CVE-2019-14834 CVE-2022-23302 CVE-2022-23305 CVE-2022-23307
|
Platform(s): | Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM SUSE Linux Enterprise Desktop 15 SP2 SUSE Linux Enterprise High Performance Computing 15 SP2 SUSE Linux Enterprise Module for Basesystem 15 SP2 SUSE Linux Enterprise Server 15 SP2 SUSE Linux Enterprise Server for SAP Applications 15 SP2 SUSE Linux Enterprise Storage 7 SUSE Manager Proxy 4.1 SUSE Manager Server 4.1
| Product(s): | |
Definition Synopsis |
SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed AND dnsmasq-2.78-7.3.1 is installed
|
Definition Synopsis |
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM is installed
AND log4j12-1.2.17-4.9.1 is installed
|