CVE-2019-17571Patch(apache / application_testing_suite)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch apache application_testing_suite systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • application_testing_suite
  • bookkeeper
  • communications_network_integrity
  • debian_linux

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 9 signals
  • General: 4 classified signals
  • Disclosure: 1 classified signal
  • Peaked 5d ago at 4 mentions (2026-03-10); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Products
application_testing_suitebookkeepercommunications_network_integritydebian_linuxendeca_information_discovery_studiofinancial_services_lending_and_leasingleaplog4jmysql_enterprise_monitoroncommand_system_manager

20 versions affected across 17 products

Deep dive

Activity timeline11 mentions / 6d
01234Mentions · 2026-03-10: 4Mentions · 2026-03-11: 2Mentions · 2026-03-17: 2Mentions · 2026-03-18: 1Mentions · 2026-08-26: 1Mentions · 2026-08-27: 1Active Exploitation · 2026-03-11: 1Patch / Workaround · 2026-03-10: 4Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-03-10: 4Technical Details · 2026-03-11: 2Technical Details · 2026-03-17: 1Technical Details · 2026-08-26: 1Technical Details · 2026-08-27: 103-1003-1103-1703-1808-2608-27
Signal classification4 categories
Patch
545.5%
General
436.4%
Disclosure
19.1%
Active Exploitation
19.1%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-104
Disclosure1Patch3
2026-03-112
Active Exploitation1Patch1
2026-03-172
General1Patch1
2026-03-181
General1
2026-08-261
General1
2026-08-271
General1
Full discourse11 posts
  • Márcio Almeida@marcioalm
    General

    @Dinosn Hey @Dinosn, it just sounds like a bypass to the original patch applied to CVE-2017-5645 (and later CVE-2019-17571) that I reported years ago to Apache. This is a very limited attack surface needing a TcpSocketServer as explained in the advisory: https://github.com/pimps/CVE-2017-5645/blob/master/log4j%20advisory.txt

    Post summary

    The user comments on a possible bypass to the patch for CVE‑2017‑5645, noting it requires a TcpSocketServer, and links to an advisory without providing new exploit details.

    0001321.5K
    2.6K followersView on X
  • iototsecnews@iototsecnews
    Patch

    SAP の 2026年3月 Patch Day:未検出だった Log4j CVE-2019-17571 などに対応 https://iototsecnews.jp/2026/03/10/sap-security-update-patch-for-multiple-vulnerabilities-that-enable-remote-code-execution/ SAP は 2026年3月の Patch Day において、計 15件のセキュリティ脆弱性を修正しました。今回のアップデートで最も警戒すべきは、システムの完全な制御を奪われる恐れのある、2 件の Critical 脆弱性です。それらの問題の原因は、長年放置されてきた旧式のライブラリと、データの復元処理における不安全なデシリアライズにあります。 最優先で対処すべき脆弱性の 1 つ目は、保険業務向けの SAP FS-QUO 800 に影響する CVE-2019-17571 (CVSS 9.8) です。2019年に世間を騒がせた Apache Log4j 1.2 が組み込まれており、認証を必要としないサーバの乗っ取りに至る恐れがあります。2つ目のCVE-2026-27685 (CVSS 9.1) は、SAP NetWeaver Enterprise Portal (7.50) に影響し、管理画面から悪意のコンテンツを読み込ませることで、システム全体の制御を奪われる可能性があります。ご利用のチームは、ご注意ください。 #CVE201917571 #CVE202627685 #Log4j #PatchTuesday #SAP #Vulnerability

    Post summary

    The article announces SAP’s March 2026 Patch Day that addresses 15 vulnerabilities, highlighting two critical ones including CVE‑2019‑17571 (Log4j) and CVE‑2026‑27685, and provides technical details such as CVSS scores, emphasizing the need to apply the update.

    02010157
    484 followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    2026年3月ぱっちちゅーずーでー ▼Microsoft 2026 年 3 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/03/202603-security-update CVE-2026-26127 .NET のサービス拒否の脆弱性 CVE-2026-21262 SQL サーバーの特権の昇格の脆弱性 ▼SAP SAP Security Patch Day - March 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/march-2026.html CVE-2019-17571 SAP Quotation Management Insurance アプリケーション (FS-QUO) におけるコードインジェクションの脆弱性 CVE-2026-27685 SAP NetWeaver Enterprise Portal 管理における安全でないデシリアライゼーション ▼Ivanti(critical系はなし) March 2026 Security Update https://www.ivanti.com/blog/march-2026-security-update CVE-2026-3483 バージョン 2026.1.1 より前の Ivanti DSM で公開されている危険な方法により、ローカルで認証された攻撃者が権限を昇格できる可能性 ▼Fortinet(critical系はなし) https://fortiguard.fortinet.com/psirt CVE-2026-22627 LLDP OUIフィールドのバッファオーバーフロー CVE-2025-54820 fgtupdates サービスによるバッファオーバーフロー ▼Adobe https://helpx.adobe.com/security.html

    Post summary

    Microsoft, SAP, Ivanti, and Fortinet have released security updates for several CVEs in March 2026, providing patches but no mention of PoCs, exploits, or active attacks.

    100201.1K
    11.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    SAP's latest security update addresses 15 flaws, including critical RCE (CVE-2019-17571) and deserialization (CVE-2026-27685) vulnerabilities. Patch now. #SAPSecurity #CVE #CyberSecurity #InfoSec #PatchAlert #Vulnerability #RCE #EnterpriseSecurity #AppSec https://securityonline.info/critical-alert-saps-latest-security-update-fixes-9-8-cvss-rce-and-deserialization-flaws/

    Post summary

    The post announces that SAP has released a patch fixing 15 flaws, including the critical RCE CVE-2019-17571 and deserialization CVE-2026-27685, urging a patch update.

    00020325
    10.6K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-3342 2 - CVE-2026-4149 3 - CVE-2026-32635 4 - CVE-2025-41237 5 - CVE-2019-17571 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists the top trending CVE identifiers, without additional context about exploitation, patches, or technical details.

    00010169
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2010-5139 2 - CVE-2026-24291 3 - CVE-2019-17571 4 - CVE-2025-47813 5 - CVE-2026-25172 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVEs but provides no additional context, technical detail, or actionable information.

    00010212
    1.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    新規のCriticalが2件 [CVE-2019-17571] Code Injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) [CVE-2026-27685] Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration SAP Security Patch Day - March 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/march-2026.html

    Post summary

    Two new critical SAP vulnerabilities are announced with technical details, alongside an upcoming patch day for remediation.

    00010450
    6.7K followersView on X
  • Levon Azevedo@Blackicelabs
    General

    @Davedivergent @cyb3rops FilteredObjectInputStream is a 2.x class, so 1.x isn't in this advisory — but that's not relief. 1.x's SocketServer reads serialized events with no filter at all: CVE-2019-17571, never fixed, EOL since 2015. The check is whether a receiver is listening, not the version.

    Post summary

    The post highlights that CVE‑2019‑17571 remains unfixed in version 1.x, where SocketServer accepts unserialized input without filtering, leaving the vulnerability potentially exploitable.

    0000029
    37 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers chained SAP vulnerabilities to achieve full compromise: exploiting code injection in Quotation Management (CVE-2019-17571) for initial access, then leveraging insecure deserialization in NetWeaver Portal (CVE-2026-27685) for privilege escalation and lateral movement. Runtime segmentation could help limit blast radius from such privilege escalation chains. #Vulnerability 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/sap-2026-critical-vulnerabilities-patched

    Post summary

    The text reports that attackers have actively exploited two SAP CVEs in a chained manner, providing technical details and indicating that patches are available.

    0000059
    1.9K followersView on X
  • Cyber News Live@cybernewslive
    Patch

    SAP has fixed three serious security flaws in its business software used by large companies to manage insurance quotes, employee portals, and supply chains. One flaw (CVE-2019-17571) dates back to 2019 and could let attackers run software on company systems remotely. SAP systems hold payroll records, HR files, and customer data — if your employer uses SAP and you receive an unexpected password reset for a work portal, or any message about changes to your employment records you didn't initiate, treat it as suspicious and contact HR directly by phone. 💥 #CyberNewsLive https://securityweek.com/sap-patches-critical-fs-quo-netweaver-vulnerabilities/

    Post summary

    SAP announced it has patched CVE‑2019‑17571, a remote code execution flaw in its enterprise software, and advises vigilance for suspicious password resets or HR changes.

    0000048
    1.6K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    SAP released 15 security notes in March 2026 patch day, fixing critical FS-QUO Log4j deserialization (CVE-2019-17571), another critical flaw (CVE-2026-27685), and high-severity SCM DoS (CVE-2026-27689). #SAPSecurity #Log4jFix #Germany https://ift.tt/AvULCN1

    Post summary

    SAP’s March 2026 patch day addressed several critical vulnerabilities, including a Log4j deserialization flaw (CVE‑2019‑17571) and a high‑severity SCM DoS (CVE‑2026‑27689), by releasing 15 security notes with patches.

    00000117
    3.7K followersView on X
CPE platform detail27 entries

27 of 27 entries

PartVendorProductVersionTarget SWTarget HW
Appapachebookkeeper---
Appapachelog4j---
OScanonicalubuntu_linux18.04--
OSdebiandebian_linux10.0--
OSdebiandebian_linux8.0--
OSdebiandebian_linux9.0--
Appnetapponcommand_system_manager---
Appnetapponcommand_workflow_automation---
OSopensuseleap15.1--
Apporacleapplication_testing_suite13.3.0.1--
Apporaclecommunications_network_integrity---
Apporacleendeca_information_discovery_studio3.2.0--
Apporaclefinancial_services_lending_and_leasing---
Apporaclefinancial_services_lending_and_leasing12.5.0--
Apporaclemysql_enterprise_monitor---
Apporacleprimavera_gateway---
Apporaclerapid_planning12.1--
Apporaclerapid_planning12.2--
Apporacleretail_extract_transform_and_load19.0--
Apporacleretail_service_backbone14.1--
Apporacleretail_service_backbone15.0--
Apporacleretail_service_backbone16.0--
Apporacleweblogic_server10.3.6.0.0--
Apporacleweblogic_server12.1.3.0.0--
Apporacleweblogic_server12.2.1.3.0--
Apporacleweblogic_server12.2.1.4.0--
Apporacleweblogic_server14.1.1.0.0--

Explore more