CVE-2018-8088: Oracle Goldengate Application Adapters
Critical severity, CVSS 9.8. EPSS: 14.7% chance of exploitation in the next 30 days.
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.
Affected products
- Oracle Goldengate Application Adapters: version 12.3.2.1.0 only
- Oracle Goldengate Stream Analytics: before 19.1.0.0.1 (fixed in 19.1.0.0.1)
- Oracle Utilities Framework: version 4.2.0.2.0 only; version 4.2.0.3.0 only; version 4.3.0.2.0 only; version 4.3.0.3.0 only; version 4.3.0.4.0 only; version 4.3.0.5.0 only; …
- Qos SLF4J: before 1.7.26 (fixed in 1.7.26); version 1.8.0 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Eus: version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Tus: version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- Red Hat JBoss Enterprise Application Platform: version 7.1 only; version 6.0.0 only; version 6.4.0 only
- Red Hat Virtualization: version 4.0 only
- Red Hat Virtualization Host: version 4.0 only
Published 2018-03-20. Last modified 2026-06-17.