CVE-2018-1285
11.05.2020, 17:15
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.Enginsight
Vendor | Product | Version |
---|---|---|
apache | log4net | 𝑥 < 2.0.10 |
oracle | application_testing_suite | 13.3.0.1 |
oracle | hospitality_opera_5 | 5.5 |
oracle | hospitality_opera_5 | 5.6 |
oracle | hospitality_simphony | 18.2.7.2 |
oracle | hospitality_simphony | 19.1.3 |
netapp | manageability_software_development_kit | - |
netapp | snapcenter | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
log4net |
|
References