Improper access control in slf4j - CVE-2018-8088
Published: March 28, 2018 / Updated: March 28, 2018
Vulnerability identifier: #VU11301
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8088
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to bypass access restrictions on the target system.
The weakness exists in the org.slf4j.ext.EventData class due to improper security restrictions. A remote attacker can send specially crafted input, bypass access restrictions and gain unauthorized access to perform further attacks.
The weakness exists in the org.slf4j.ext.EventData class due to improper security restrictions. A remote attacker can send specially crafted input, bypass access restrictions and gain unauthorized access to perform further attacks.
Affected software
slf4j
PowerStore 9000X
PowerStore 7000X
PowerStore 5000X
PowerStore 3000X
PowerStore 1000X
PowerStoreX OS
Red Hat Software Collections
z/Transaction Processing Facility ( z/TPF)
IBM Sterling Secure Proxy
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
Red Hat Virtualization Host
Red Hat Virtualization
JBoss Data Virtualization
JBoss Enterprise Application Platform
Fuse
Oracle WebLogic Server
JBoss Data Grid
Oracle GoldenGate Application Adapters
openSUSE Leap
slf4j
PowerStore T
IBM Secure External Authentication Server
Operational Decision Manager
PowerStore 9000X
PowerStore 7000X
PowerStore 5000X
PowerStore 3000X
PowerStore 1000X
PowerStoreX OS
Red Hat Software Collections
z/Transaction Processing Facility ( z/TPF)
IBM Sterling Secure Proxy
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
Red Hat Virtualization Host
Red Hat Virtualization
JBoss Data Virtualization
JBoss Enterprise Application Platform
Fuse
Oracle WebLogic Server
JBoss Data Grid
Oracle GoldenGate Application Adapters
openSUSE Leap
slf4j
PowerStore T
IBM Secure External Authentication Server
Operational Decision Manager
How to mitigate CVE-2018-8088
Update to version 1.8.0-beta2.
JBoss Data Virtualization - update to 6.4.8
Fuse - addressed in versions 7.1.0, 7.4.0
slf4j - addressed in versions 1.7.22-5.fc26, 1.7.25-4.fc27, 1.7.25-4.fc28
PowerStoreX OS - update to 3.2.1.6-2476179
PowerStore T - update to 3.5.0.1-2083289
IBM Secure External Authentication Server - addressed in versions 6.0.3.0 iFix 10, 6.1.0.0 iFix 06
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
Fuse - addressed in versions 7.1.0, 7.4.0
slf4j - addressed in versions 1.7.22-5.fc26, 1.7.25-4.fc27, 1.7.25-4.fc28
PowerStoreX OS - update to 3.2.1.6-2476179
PowerStore T - update to 3.5.0.1-2083289
IBM Secure External Authentication Server - addressed in versions 6.0.3.0 iFix 10, 6.1.0.0 iFix 06
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
External References
Related Security Bulletins
- Security restrictions bypass in Quality Open Software slf4j
- Red Hat update for Quality Open Software slf4j
- Red Hat update for Quality Open Software slf4j
- Red Hat update for Quality Open Software slf4j
- Red Hat update for Quality Open Software slf4j
- Red Hat update for Quality Open Software slf4j
- Red Hat update for Quality Open Software slf4j
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- Red Hat update for Quality Open Software slf4j
- Red Hat update for jackson-databind
- Red Hat update for jboss
- Red Hat update for jboss
- Red Hat update for jboss
- Red Hat update for jboss
- OpenSUSE Linux update for slf4j
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in Red Hat JBoss Data Virtualization
- Multiple vulnerabilities in Oracle GoldenGate Application Adapters
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in z/Transaction Processing Facility
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in IBM Secure External Authentication Server
- Multiple vulnerabilities in IBM Secure Proxy
- Multiple vulnerabilities in IBM Operational Decision Manager
- Fedora 26 update for slf4j
- Fedora 27 update for slf4j
- Fedora 28 update for slf4j
- Multiple vulnerabilities in Dell PowerStore X
- Multiple vulnerabilities in Fuse 7