CVE-2018-8088: Oracle Goldengate Application Adapters

Critical severity, CVSS 9.8. EPSS: 14.7% chance of exploitation in the next 30 days.

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.

Affected products

  • Oracle Goldengate Application Adapters: version 12.3.2.1.0 only
  • Oracle Goldengate Stream Analytics: before 19.1.0.0.1 (fixed in 19.1.0.0.1)
  • Oracle Utilities Framework: version 4.2.0.2.0 only; version 4.2.0.3.0 only; version 4.3.0.2.0 only; version 4.3.0.3.0 only; version 4.3.0.4.0 only; version 4.3.0.5.0 only; …
  • Qos SLF4J: before 1.7.26 (fixed in 1.7.26); version 1.8.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.4 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server Tus: version 7.4 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat JBoss Enterprise Application Platform: version 7.1 only; version 6.0.0 only; version 6.4.0 only
  • Red Hat Virtualization: version 4.0 only
  • Red Hat Virtualization Host: version 4.0 only

Published 2018-03-20. Last modified 2026-06-17.