← Vulnerability feed

Vulnerability record · CVE-2022-23302 · published 18 January 2022

CVE-2022-23302: Apache Log4j 1.x JMSSink JNDI deserialization remote code execution

Apache · Log4j

JMSSink in all versions of Log4j 1.x deserializes untrusted data when an attacker can write to the Log4j configuration or when the configuration references an attacker-controlled LDAP service. A crafted TopicConnectionFactoryBindingName value causes JMSSink to issue JNDI requests that can lead to remote code execution, similar to CVE-2021-4104. The issue only affects Log4j 1.x when JMSSink is explicitly configured, which is not the default, and Log4j 1.2 has been end-of-life since August 2015.

8.8 CVSS 3.1 High EPSS 64% · top 0.8% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score, v2 6.0
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
26Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 8.8 and a very high EPSS percentile indicate significant risk, but exploitation requires non-default JMSSink configuration and low-privileged access to configuration or LDAP, and the flaw is not in CISA KEV.

What it is

JMSSink in all versions of Log4j 1.x deserializes untrusted data when an attacker can write to the Log4j configuration or when the configuration references an attacker-controlled LDAP service. A crafted TopicConnectionFactoryBindingName value causes JMSSink to issue JNDI requests that can lead to remote code execution, similar to CVE-2021-4104. The issue only affects Log4j 1.x when JMSSink is explicitly configured, which is not the default, and Log4j 1.2 has been end-of-life since August 2015.

Impact

An attacker who can influence the Log4j configuration or an LDAP service it references can execute arbitrary code in the context of the affected application. CVSS 3.1 scores this 8.8 (High) with high confidentiality, integrity and availability impact.

Attack surface

Reachable over the network (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N), but it requires low privileges (PR:L) because the attacker must have write access to the Log4j configuration or control of a referenced LDAP service. It is not exploitable in default configurations; JMSSink must be specifically enabled.

Exploitation

CVE-2022-23302 is not listed in CISA KEV and has no documented ransomware use, but EPSS is high at 0.63556 (99.175th percentile), indicating elevated predicted exploitation activity. References include vendor advisories and Oracle patch notices, but no public exploit code is cited in the record.

What to do

  • Upgrade from Log4j 1.x to Log4j 2, which is the vendor-recommended fix and addresses this and other issues.
  • If upgrade is not immediately possible, remove or disable JMSSink usage and avoid referencing untrusted LDAP services in Log4j configuration.
  • Restrict write access to Log4j configuration files to trusted administrators only.
  • Apply vendor patches for affected products (for example Oracle CPU April/July 2022 advisories) where Log4j 1.x is bundled.
  • Monitor and block outbound JNDI/LDAP connections from application servers that do not require them.

Detection

  • Search application and server logs for JMSSink initialization and JNDI/LDAP lookups originating from Log4j 1.x components.
  • Monitor file integrity on Log4j configuration files for unauthorized changes, especially TopicConnectionFactoryBindingName entries.
  • Detect outbound LDAP or JNDI traffic from Java application servers to unexpected or external hosts.
  • Inventory applications and dependencies for Log4j 1.x and flag any that use JMSSink.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

26 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-23302 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed9.0CVE-2021-45046Apache Log4j 2.15.0 Incomplete Fix Allows JNDI Lookup InjectionThe fix for CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. When a non-default Pattern Layout uses a Cont…KEVEPSS 100%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed7.5CVE-2020-14864Oracle Business Intelligence Enterprise Edition path traversal allows unauthenticated data accessOracle Business Intelligence Enterprise Edition contains a path traversal flaw in its Installation component affecting versions 5.5.0.0.0, 12.2.1.3.0…KEVEPSS 97%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.8CVE-2024-4173Broadcom brocade sannav information exposure vulnerabilityA vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various at…EPSS 0.59%9.8CVE-2024-29966Broadcom brocade sannav hard-coded credentials vulnerabilityBrocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vu…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2022-23302), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.