Oval Definition:
oval:org.opensuse.security:def:126902
Revision Date
:
2022-01-27
Version
:
1
Title
:
Security update for log4j (Important)
Description
:
This update for log4j fixes the following issues:
- CVE-2022-23307: Fix deserialization issue by removing the chainsaw sub-package. (bsc#1194844) - CVE-2022-23305: Fix SQL injection by removing src/main/java/org/apache/log4j/jdbc/JDBCAppender.java. (bsc#1194843) - CVE-2022-23302: Fix remote code execution by removing src/main/java/org/apache/log4j/net/JMSSink.java. (bsc#1194842)
Family
:
unix
Class
:
patch
Status
:
Reference(s)
:
1194842
1194843
1194844
CVE-2022-23302
CVE-2022-23305
CVE-2022-23307
Platform(s)
:
SUSE Linux Enterprise Server 12 SP4-ESPOS
Product(s)
:
Definition Synopsis
SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
AND
log4j-1.2.15-126.9.1 is installed
BACK