← Vulnerability feed

Vulnerability record · CVE-2022-23307 · published 18 January 2022

CVE-2022-23307: Apache Chainsaw and Log4j 1.2.x Deserialization of Untrusted Data

Apache · Chainsaw

CVE-2022-23307 is a deserialization of untrusted data flaw (CWE-502) that was originally identified in Apache Chainsaw as CVE-2020-9493. The same issue exists in Apache Log4j 1.2.x, where Chainsaw was a component prior to Chainsaw V2.0, and it also affects the reload4j fork and multiple Oracle products that bundle these libraries.

8.8 CVSS 3.1 High EPSS 54% · top 1.0% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score, v2 9.0
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
26Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 8.8 and a 99th-percentile EPSS score indicate a serious, likely-exploitable deserialization flaw, though it is not in KEV and requires some privileges.

What it is

CVE-2022-23307 is a deserialization of untrusted data flaw (CWE-502) that was originally identified in Apache Chainsaw as CVE-2020-9493. The same issue exists in Apache Log4j 1.2.x, where Chainsaw was a component prior to Chainsaw V2.0, and it also affects the reload4j fork and multiple Oracle products that bundle these libraries.

Impact

An attacker who can supply crafted serialized data can trigger deserialization of untrusted input, leading to high impact on confidentiality, integrity and availability. Successful exploitation can result in remote code execution or full compromise of the affected process.

Attack surface

The CVSS vector AV:N/AC:L/PR:L/UI:N indicates the flaw is reachable over the network with low attack complexity, but requires the attacker to hold some level of privileges and no user interaction. The record does not specify the exact protocol or endpoint, so the precise entry point cannot be confirmed from the supplied data.

Exploitation

The CVE is not listed in CISA KEV and no ransomware groups are documented as using it, but EPSS is high at 0.54411 (99th percentile), indicating a meaningful probability of exploitation activity. Reference tags show only vendor advisories and Oracle patches, with no public exploit or PoC tags.

What to do

  • Apply the Oracle CPU April 2022 and July 2022 patches for affected Oracle products.
  • Upgrade Apache Chainsaw to V2.0 or later, where the deserialization issue is addressed.
  • Migrate off Apache Log4j 1.2.x and reload4j to a maintained logging framework, or apply the vendor-recommended fix for the 1.2.x branch.
  • Restrict network access to services that deserialize data so that only trusted, authenticated clients can reach them.
  • Where deserialization cannot be avoided, enforce strict allow-list based object filtering on serialized input.

Detection

  • Monitor application and server logs for deserialization errors, class-cast exceptions, or unexpected gadget-chain class loading.
  • Alert on network connections to services that use Log4j 1.2.x or Chainsaw from untrusted or unusual source addresses.
  • Use runtime instrumentation or EDR to detect suspicious object deserialization and subsequent process execution in Java workloads.
  • Inventory hosts and applications still running Log4j 1.2.x, reload4j, or Chainsaw prior to V2.0 and flag them for remediation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

26 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-23307 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed9.0CVE-2021-45046Apache Log4j 2.15.0 Incomplete Fix Allows JNDI Lookup InjectionThe fix for CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. When a non-default Pattern Layout uses a Cont…KEVEPSS 100%analysed7.5CVE-2020-14864Oracle Business Intelligence Enterprise Edition path traversal allows unauthenticated data accessOracle Business Intelligence Enterprise Edition contains a path traversal flaw in its Installation component affecting versions 5.5.0.0.0, 12.2.1.3.0…KEVEPSS 97%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.9CVE-2026-60542Oracle business process management suite improper access control vulnerabilityVulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow). Supported versions tha…EPSS 0.43%9.8CVE-2022-23305Log4j 1.x JDBCAppender SQL injection via logged inputThe JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m mes…EPSS 67%analysed9.8CVE-2021-2456Oracle Business Intelligence Enterprise Edition unauthenticated takeoverOracle Business Intelligence Enterprise Edition 12.2.1.4.0 contains a flaw in the Analytics Web General component that is reachable over HTTP without…EPSS 81%analysed

Source: NIST National Vulnerability Database (record CVE-2022-23307), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.