9.8

CVE-2018-8088

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.

Data is provided by the National Vulnerability Database (NVD)
QosSlf4j Version < 1.7.26
QosSlf4j Version1.8.0 Updatealpha1
QosSlf4j Version1.8.0 Updatealpha2
QosSlf4j Version1.8.0 Updatebeta1
QosSlf4j Version1.8.0 Updatebeta2
RedhatJboss Enterprise Application Platform Version7.1
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
RedhatJboss Enterprise Application Platform Version6.0.0
   RedhatEnterprise Linux Version5.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
RedhatJboss Enterprise Application Platform Version6.4.0
   RedhatEnterprise Linux Version5.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
RedhatVirtualization Version4.0
   RedhatEnterprise Linux Server Version7.0
RedhatVirtualization Host Version4.0
   RedhatEnterprise Linux Server Version7.0
RedhatEnterprise Linux Eus Version7.4
RedhatEnterprise Linux Eus Version7.5
RedhatEnterprise Linux Eus Version7.6
RedhatEnterprise Linux Eus Version7.7
OracleGoldengate Application Adapters Version12.3.2.1.0
OracleGoldengate Stream Analytics Version < 19.1.0.0.1
OracleUtilities Framework Version4.2.0.2.0
OracleUtilities Framework Version4.2.0.3.0
OracleUtilities Framework Version4.3.0.2.0
OracleUtilities Framework Version4.3.0.3.0
OracleUtilities Framework Version4.3.0.4.0
OracleUtilities Framework Version4.3.0.5.0
OracleUtilities Framework Version4.3.0.6.0
OracleUtilities Framework Version4.4.0.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.84% 0.725
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
http://www.securityfocus.com/bid/103737
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1040627
Third Party Advisory
VDB Entry
https://jira.qos.ch/browse/SLF4J-430
Vendor Advisory
Issue Tracking
https://jira.qos.ch/browse/SLF4J-431
Vendor Advisory
Issue Tracking