Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2022-23307 Details
Description
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 22, 2026Exploitation: NoneAutomatable: NoTechnical Impact: Total
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh | CVE | Mailing ListVendor Advisory |
| https://logging.apache.org/log4j/1.2/index.html | CVE | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | CVE | PatchThird Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html | CVE | PatchThird Party Advisory |
| https://lists.apache.org/thread/rg4yyc89vs3dw6kpy3r92xop9loywyhh | [email protected] | Mailing ListVendor Advisory |
| https://logging.apache.org/log4j/1.2/index.html | [email protected] | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | [email protected] | PatchThird Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html | [email protected] | PatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache chainsaw | < 2.1.0 |
CPE
Remediation
| |
| apache log4j | >= 1.2, < 2.0 |
CPE
Remediation
| |
| qos reload4j | < 1.2.18.1 |
CPE
Remediation
| |
| oracle advanced supply chain planning | 12.1 12.2 |
CPE
Remediation
| |
| oracle business intelligence | 5.9.0.0.0 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle business process management suite | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle communications eagle ftp table base retrieval | 4.5 |
CPE
Remediation
| |
| oracle communications instant messaging server | 10.0.1.5.0 |
CPE
Remediation
| |
| oracle communications messaging server | 8.1 |
CPE
Remediation
| |
| oracle communications network integrity | 7.3.6 |
CPE
Remediation
| |
| oracle communications offline mediation controller | < 12.0.0.4.4 12.0.0.5.0 |
CPE
Remediation
| |
| oracle communications unified inventory management | 7.4.1 7.4.2 |
CPE
Remediation
| |
| oracle e-business suite cloud manager and cloud backup module | < 2.2.1.1.1 2.2.1.1.1 |
CPE
Remediation
| |
| oracle enterprise manager base platform | 13.4.0.0 13.5.0.0 |
CPE
Remediation
| |
| oracle financial services revenue management and billing analytics | 2.7.0.0 2.7.0.1 2.8.0.0 |
CPE
Remediation
| |
| oracle healthcare foundation | 8.1.0 |
CPE
Remediation
| |
| oracle hyperion data relationship management | < 11.2.8.0 |
CPE
Remediation
| |
| oracle hyperion infrastructure technology | < 11.2.8.0 |
CPE
Remediation
| |
| oracle identity management suite | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle identity manager connector | 11.1.1.5.0 |
CPE
Remediation
| |
| oracle jdeveloper | 12.2.1.3.0 |
CPE
Remediation
| |
| oracle middleware common libraries and tools | 12.2.1.4.0 |
CPE
Remediation
| |
| oracle mysql enterprise monitor | <= 8.0.29 |
CPE
Remediation
| |
| oracle retail extract transform and load | 13.2.5 |
CPE
Remediation
| |
| oracle tuxedo | 12.2.2.0.0 |
CPE
Remediation
| |
| oracle weblogic server | 12.2.1.3.0 12.2.1.4.0 14.1.1.0.0 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 22, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 24, 2023 | Modified Analysis | [email protected] |
| Jul 25, 2022 | CVE Modified | [email protected] |
| Jun 16, 2022 | Modified Analysis | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Apr 14, 2022 | Reanalysis | [email protected] |
| Apr 8, 2022 | Reanalysis | [email protected] |
| Jan 24, 2022 | Initial Analysis | [email protected] |