Improper access control in slf4j - CVE-2018-8088

 

Improper access control in slf4j - CVE-2018-8088

Published: March 28, 2018 / Updated: March 28, 2018


Vulnerability identifier: #VU11301
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8088
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to bypass access restrictions on the target system.

The weakness exists in the org.slf4j.ext.EventData class due to improper security restrictions. A remote attacker can send specially crafted input, bypass access restrictions and gain unauthorized access to perform further attacks.

Affected software

slf4j
PowerStore 9000X
PowerStore 7000X
PowerStore 5000X
PowerStore 3000X
PowerStore 1000X
PowerStoreX OS
Red Hat Software Collections
z/Transaction Processing Facility ( z/TPF)
IBM Sterling Secure Proxy
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
Red Hat Virtualization Host
Red Hat Virtualization
JBoss Data Virtualization
JBoss Enterprise Application Platform
Fuse
Oracle WebLogic Server
JBoss Data Grid
Oracle GoldenGate Application Adapters
openSUSE Leap
slf4j
PowerStore T
IBM Secure External Authentication Server
Operational Decision Manager

How to mitigate CVE-2018-8088

Update to version 1.8.0-beta2.

JBoss Data Virtualization - update to 6.4.8
Fuse - addressed in versions 7.1.0, 7.4.0
slf4j - addressed in versions 1.7.22-5.fc26, 1.7.25-4.fc27, 1.7.25-4.fc28
PowerStoreX OS - update to 3.2.1.6-2476179
PowerStore T - update to 3.5.0.1-2083289
IBM Secure External Authentication Server - addressed in versions 6.0.3.0 iFix 10, 6.1.0.0 iFix 06
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5

External References

Related Security Bulletins