Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-1288


In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.


Published

2018-07-26T14:29:00.547

Last Modified

2024-11-21T03:59:33.153

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache kafka ≤ 0.9.0.1 Yes
Application apache kafka ≤ 0.10.2.1 Yes
Application apache kafka ≤ 0.11.0.2 Yes
Application apache kafka 1.0.0 Yes
Application redhat jboss_middleware_text-only_advisories 1.0 Yes
Application oracle database 11.2.0.4 Yes
Application oracle database 12.1.0.2 Yes
Application oracle database 12.2.0.1 Yes
Application oracle database 18c Yes
Application oracle database 19c Yes
Application oracle primavera_p6_enterprise_project_portfolio_management ≤ 19.12.6.0 Yes
Application oracle timesten_in-memory_database < 18.1.2.1.0 Yes

References