Is Messaging Gateway vulnerable to CVE-2019-17571 SocketServer class vulnerability?
search cancel

Is Messaging Gateway vulnerable to CVE-2019-17571 SocketServer class vulnerability?

book

Article ID: 232634

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

A vulnerability scanner has indicated that Messaging Gateway (SMG) may be vulnerable to the CVE-2019-17571 SocketServer data deserialization vulnerability.

The Log4j 1.2 SocketServer class is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

Resolution

Messaging Gateway (SMG) is not affected by this vulnerability. The org.apache.log4j.net.SocketServer class is not used.

Additional Information