Improper input validation in Oracle Hospitality Simphony - CVE-2018-1285
Published: January 20, 2021
Vulnerability identifier: #VU49772
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1285
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Simphony Server (Apache log4net) component in Oracle Hospitality Simphony. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
Affected software
Oracle Hospitality Simphony
Oracle Hospitality OPERA 5
Fedora
Ubuntu
Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)
Oracle Application Testing Suite
Enterprise Manager Base Platform
liblog4net1.2-cil (Ubuntu package)
log4net
OptiPlex 3240 All-in-One
OptiPlex 3046
OptiPlex 5040
OptiPlex 7040
OptiPlex 7440 All-In-One
Precision 3420 Tower
Precision 3510
Precision 3620 Tower
Precision 5510
Precision 5530 2-in-1
Vostro 3267
Vostro 3268
Vostro 3660
Vostro 3667
Vostro 3668
Vostro 3669
Wyse 7040 Thin Client
XPS 13 (9370)
XPS 15 9575 2-in-1
Inspiron 15 3567
Latitude 3580
Latitude 3480
Latitude 7280
Latitude 14 Rugged 5414
Latitude 3379
Latitude 3390
Latitude 5280
Latitude 5288
Latitude 5480
Latitude 5488
Latitude 5580
Latitude 7212 Rugged Extreme Tablet
Latitude 7214 Rugged Extreme
Latitude 7275 2-in-1
Latitude 13 3380
Latitude 7370
Latitude 7380
Latitude 7414
Latitude 7480
Latitude E5270
Latitude E5470
Latitude E5570
Latitude E7270
Latitude E7470
OptiPlex 3040
Embedded Box PC 5000
Oracle Hospitality OPERA 5
Fedora
Ubuntu
Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)
Oracle Application Testing Suite
Enterprise Manager Base Platform
liblog4net1.2-cil (Ubuntu package)
log4net
OptiPlex 3240 All-in-One
OptiPlex 3046
OptiPlex 5040
OptiPlex 7040
OptiPlex 7440 All-In-One
Precision 3420 Tower
Precision 3510
Precision 3620 Tower
Precision 5510
Precision 5530 2-in-1
Vostro 3267
Vostro 3268
Vostro 3660
Vostro 3667
Vostro 3668
Vostro 3669
Wyse 7040 Thin Client
XPS 13 (9370)
XPS 15 9575 2-in-1
Inspiron 15 3567
Latitude 3580
Latitude 3480
Latitude 7280
Latitude 14 Rugged 5414
Latitude 3379
Latitude 3390
Latitude 5280
Latitude 5288
Latitude 5480
Latitude 5488
Latitude 5580
Latitude 7212 Rugged Extreme Tablet
Latitude 7214 Rugged Extreme
Latitude 7275 2-in-1
Latitude 13 3380
Latitude 7370
Latitude 7380
Latitude 7414
Latitude 7480
Latitude E5270
Latitude E5470
Latitude E5570
Latitude E7270
Latitude E7470
OptiPlex 3040
Embedded Box PC 5000
How to mitigate CVE-2018-1285
Install updates from vendor's website.
Foxit PDF Reader for Windows - update to 11.2.1.53537
Foxit PDF Editor (formerly Foxit PhantomPDF) - update to 11.2.1.53537
liblog4net1.2-cil (Ubuntu package) - addressed in versions 1.2.10+dfsg-7ubuntu0.16.04.1, 1.2.10+dfsg-7ubuntu0.18.04.1, 1.2.10+dfsg-7ubuntu0.20.04.1, 1.2.10+dfsg-7ubuntu0.20.10.1
log4net - addressed in versions 2.0.8-10.el7, 2.0.8-10.el8, 2.0.8-10.fc30, 2.0.8-10.fc31, 2.0.8-10.fc32
OptiPlex 3240 All-in-One - update to 16.8.4.1011
OptiPlex 3046 - update to 16.8.4.1011
OptiPlex 5040 - update to 16.8.4.1011
OptiPlex 7040 - update to 16.8.4.1011
OptiPlex 7440 All-In-One - update to 16.8.4.1011
Precision 3420 Tower - update to 16.8.4.1011
Precision 3510 - update to 16.8.4.1011
Precision 3620 Tower - update to 16.8.4.1011
Precision 5510 - update to 16.8.4.1011
Precision 5530 2-in-1 - update to 16.8.4.1011
Vostro 3267 - update to 16.8.4.1011
Vostro 3268 - update to 16.8.4.1011
Vostro 3660 - update to 16.8.4.1011
Vostro 3667 - update to 16.8.4.1011
Vostro 3668 - update to 16.8.4.1011
Vostro 3669 - update to 16.8.4.1011
Wyse 7040 Thin Client - update to 16.8.4.1011
XPS 13 (9370) - update to 16.8.4.1011
XPS 15 9575 2-in-1 - update to 16.8.4.1011
Inspiron 15 3567 - update to 16.8.4.1011
Embedded Box PC 5000 - update to 16.8.4.1011
Latitude 3580 - update to 16.8.4.1011
Latitude 3480 - update to 16.8.4.1011
Latitude 7280 - update to 16.8.4.1011
Latitude 14 Rugged 5414 - update to 16.8.4.1011
Latitude 3379 - update to 16.8.4.1011
Latitude 3390 - update to 16.8.4.1011
Latitude 5280 - update to 16.8.4.1011
Latitude 5288 - update to 16.8.4.1011
Latitude 5480 - update to 16.8.4.1011
Latitude 5488 - update to 16.8.4.1011
Latitude 5580 - update to 16.8.4.1011
Latitude 7212 Rugged Extreme Tablet - update to 16.8.4.1011
Latitude 7214 Rugged Extreme - update to 16.8.4.1011
Latitude 7275 2-in-1 - update to 16.8.4.1011
Latitude 13 3380 - update to 16.8.4.1011
Latitude 7370 - update to 16.8.4.1011
Latitude 7380 - update to 16.8.4.1011
Latitude 7414 - update to 16.8.4.1011
Latitude 7480 - update to 16.8.4.1011
Latitude E5270 - update to 16.8.4.1011
Latitude E5470 - update to 16.8.4.1011
Latitude E5570 - update to 16.8.4.1011
Latitude E7270 - update to 16.8.4.1011
Latitude E7470 - update to 16.8.4.1011
OptiPlex 3040 - update to 16.8.4.1011
Foxit PDF Editor (formerly Foxit PhantomPDF) - update to 11.2.1.53537
liblog4net1.2-cil (Ubuntu package) - addressed in versions 1.2.10+dfsg-7ubuntu0.16.04.1, 1.2.10+dfsg-7ubuntu0.18.04.1, 1.2.10+dfsg-7ubuntu0.20.04.1, 1.2.10+dfsg-7ubuntu0.20.10.1
log4net - addressed in versions 2.0.8-10.el7, 2.0.8-10.el8, 2.0.8-10.fc30, 2.0.8-10.fc31, 2.0.8-10.fc32
OptiPlex 3240 All-in-One - update to 16.8.4.1011
OptiPlex 3046 - update to 16.8.4.1011
OptiPlex 5040 - update to 16.8.4.1011
OptiPlex 7040 - update to 16.8.4.1011
OptiPlex 7440 All-In-One - update to 16.8.4.1011
Precision 3420 Tower - update to 16.8.4.1011
Precision 3510 - update to 16.8.4.1011
Precision 3620 Tower - update to 16.8.4.1011
Precision 5510 - update to 16.8.4.1011
Precision 5530 2-in-1 - update to 16.8.4.1011
Vostro 3267 - update to 16.8.4.1011
Vostro 3268 - update to 16.8.4.1011
Vostro 3660 - update to 16.8.4.1011
Vostro 3667 - update to 16.8.4.1011
Vostro 3668 - update to 16.8.4.1011
Vostro 3669 - update to 16.8.4.1011
Wyse 7040 Thin Client - update to 16.8.4.1011
XPS 13 (9370) - update to 16.8.4.1011
XPS 15 9575 2-in-1 - update to 16.8.4.1011
Inspiron 15 3567 - update to 16.8.4.1011
Embedded Box PC 5000 - update to 16.8.4.1011
Latitude 3580 - update to 16.8.4.1011
Latitude 3480 - update to 16.8.4.1011
Latitude 7280 - update to 16.8.4.1011
Latitude 14 Rugged 5414 - update to 16.8.4.1011
Latitude 3379 - update to 16.8.4.1011
Latitude 3390 - update to 16.8.4.1011
Latitude 5280 - update to 16.8.4.1011
Latitude 5288 - update to 16.8.4.1011
Latitude 5480 - update to 16.8.4.1011
Latitude 5488 - update to 16.8.4.1011
Latitude 5580 - update to 16.8.4.1011
Latitude 7212 Rugged Extreme Tablet - update to 16.8.4.1011
Latitude 7214 Rugged Extreme - update to 16.8.4.1011
Latitude 7275 2-in-1 - update to 16.8.4.1011
Latitude 13 3380 - update to 16.8.4.1011
Latitude 7370 - update to 16.8.4.1011
Latitude 7380 - update to 16.8.4.1011
Latitude 7414 - update to 16.8.4.1011
Latitude 7480 - update to 16.8.4.1011
Latitude E5270 - update to 16.8.4.1011
Latitude E5470 - update to 16.8.4.1011
Latitude E5570 - update to 16.8.4.1011
Latitude E7270 - update to 16.8.4.1011
Latitude E7470 - update to 16.8.4.1011
OptiPlex 3040 - update to 16.8.4.1011
External References
Related Security Bulletins
- Improper input validation in Oracle Hospitality Simphony
- Multiple vulnerabilities in Oracle Hospitality OPERA 5
- Multiple vulnerabilities in Foxit PDF Reader and Editor for Windows
- Improper input validation in Oracle Application Testing Suite
- Ubuntu update for log4net
- Dell client security update for Intel RST
- Multiple vulnerabilities in Enterprise Manager Base Platform
- Fedora 32 update for log4net
- Fedora 31 update for log4net
- Fedora 30 update for log4net
- Fedora EPEL 7 update for log4net
- Fedora EPEL 8 update for log4net