CVE-2018-1285
published 2020-05-11CVE-2018-1285: Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in…
PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
17.37%
96.8th percentile
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4net | < 2.0.10 | 2.0.10 |
| apache | log4net | >= 0 < 1.2.10+dfsg-8 | 1.2.10+dfsg-8 |
| apache | log4net | >= 0 < 1.2.10+dfsg-8 | 1.2.10+dfsg-8 |
| apache | log4net | >= 0 < 2.0.10 | 2.0.10 |
| debian | log4net | < log4net 1.2.10+dfsg-8 (bullseye) | log4net 1.2.10+dfsg-8 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | application_testing_suite | — | — |
| oracle | hospitality_opera_5 | — | — |
| oracle | hospitality_opera_5 | — | — |
| oracle | hospitality_simphony | — | — |
| oracle | hospitality_simphony | — | — |
| quest | kace_desktop_authority | >= 10.0 < 11.2 | 11.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target applications that parse attacker-controlled log4net configuration files — XXE is triggered during XML parsing of those config files ↗
- →Flag inbound HTTP requests delivering or referencing log4net configuration files to vulnerable endpoints (remote exploit, no auth required, low complexity) ↗
- →Monitor for XXE-based out-of-band data exfiltration (DNS/HTTP callbacks) originating from processes hosting log4net on affected versions prior to 2.0.10 ↗
- →Quest KACE Desktop Authority before 11.2 is a known affected product — monitor for suspicious log4net config file writes or replacements on those hosts ↗
- →Rockwell Automation FactoryTalk Historian ThingWorx (95057C-FTHTWXCT11) v4.02.00 and prior are affected ICS products — alert on unexpected XML config file modifications in those environments ↗
- ·Vulnerability only manifests when an attacker can supply or modify the log4net configuration file — exploitation requires that attack surface to be exposed ↗
- ·No known public exploitation specifically targeting this vulnerability has been reported to CISA as of the advisory date ↗
- ·Fixed version threshold is log4net 2.0.10; Debian packages fixed in 1.2.10+dfsg-8 — ensure version checks account for both upstream and distro-repackaged version strings ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation FactoryTalk Historian ThingWorx
cisa_ics·2025-05-22·CVSS 9.8
[CRITICAL] Rockwell Automation FactoryTalk Historian ThingWorx
ICS Advisory
##
Rockwell Automation FactoryTalk Historian ThingWorx
Release DateMay 22, 2025
Alert CodeICSA-25-142-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Rockwell Automation
- Equipment: 95057C-FTHTWXCT11
- Vulnerability: Improper Restriction of XML External Entity Reference
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to launch XXE-based attacks on applications that accept malicious log4net configuration files.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Rockwell Automation FactoryTalk Historian ThingWorx are af
CISA ICS
Rockwell Automation AADvance Standalone OPC-DA Server
cisa_ics·2024-08-13·CVSS 5.0
[MEDIUM] Rockwell Automation AADvance Standalone OPC-DA Server
ICS Advisory
##
Rockwell Automation AADvance Standalone OPC-DA Server
Release DateAugust 13, 2024
Alert CodeICSA-24-226-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Rockwell Automation
- Equipment: AADvance Standalone OPC-DA Server
- Vulnerabilities: Improper Input Validation, Use of Externally Controlled Format String
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code in the affected product.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Rockwell Automation AADvance Standalone OPC-DA Server are af
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Management (Apache log4net) — CVE-2018-1285
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2018-1285 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Management (Apache log4net) — CVE-2018-1285
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Management (Apache log4net) vulnerability
CVE: CVE-2018-1285
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache log4net) — CVE-2018-1285
vendor_oracle·2022-04-15·CVSS 9.8
CVE-2018-1285 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache log4net) — CVE-2018-1285
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache log4net) vulnerability
CVE: CVE-2018-1285
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Hospitality Applications Risk Matrix: Logging (Apache log4net) — CVE-2018-1285
vendor_oracle·2021-04-15·CVSS 9.8
CVE-2018-1285 [CRITICAL] Oracle Oracle Hospitality Applications Risk Matrix: Logging (Apache log4net) — CVE-2018-1285
Oracle Oracle Hospitality Applications Risk Matrix: Logging (Apache log4net) vulnerability
CVE: CVE-2018-1285
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Ubuntu
Apache Log4net vulnerability
vendor_ubuntu·2021-01-19
CVE-2018-1285 Apache Log4net vulnerability
Title: Apache Log4net vulnerability
Summary: Apache Log4net could made to expose sensitive information if it
received a specially crafted configuration file.
It was discovered that Apache Log4net incorrectly handled certain configuration files.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Food and Beverage Applications Risk Matrix: Simphony Server (Apache log4net) — CVE-2018-1285
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2018-1285 [CRITICAL] Oracle Oracle Food and Beverage Applications Risk Matrix: Simphony Server (Apache log4net) — CVE-2018-1285
Oracle Oracle Food and Beverage Applications Risk Matrix: Simphony Server (Apache log4net) vulnerability
CVE: CVE-2018-1285
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Debian
CVE-2018-1285: log4net - Apache log4net versions before 2.0.10 do not disable XML external entities when ...
vendor_debian·2018·CVSS 9.8
CVE-2018-1285 [CRITICAL] CVE-2018-1285: log4net - Apache log4net versions before 2.0.10 do not disable XML external entities when ...
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
Scope: local
bullseye: resolved (fixed in 1.2.10+dfsg-8)
sid: resolved (fixed in 1.2.10+dfsg-8)
trixie: resolved (fixed in 1.2.10+dfsg-8)
GHSA
GHSA-6vh7-mxw3-7f49: XXE can occur in Quest KACE Desktop Authority before 11
ghsa_unreviewed·2021-12-23·CVSS 9.8
CVE-2021-44028 [CRITICAL] CWE-611 GHSA-6vh7-mxw3-7f49: XXE can occur in Quest KACE Desktop Authority before 11
XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.
GHSA
XML External Entity attack in log4net
ghsa·2021-01-29
CVE-2018-1285 [CRITICAL] CWE-611 XML External Entity attack in log4net
XML External Entity attack in log4net
Apache log4net before 2.0.10 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.
OSV
XML External Entity attack in log4net
osv·2021-01-29
CVE-2018-1285 [CRITICAL] XML External Entity attack in log4net
XML External Entity attack in log4net
Apache log4net before 2.0.10 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.
OSV
CVE-2018-1285: Apache log4net versions before 2
osv·2020-05-11·CVSS 9.8
CVE-2018-1285 [CRITICAL] CVE-2018-1285: Apache log4net versions before 2
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users [fedora-all]
bugzilla·2020-05-15·CVSS 9.8
CVE-2018-1285 [CRITICAL] CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users [fedora-all]
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users [epel-all]
bugzilla·2020-05-15·CVSS 9.8
CVE-2018-1285 [CRITICAL] CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users [epel-all]
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users
bugzilla·2020-05-14·CVSS 9.8
CVE-2018-1285 [CRITICAL] CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users
CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users
Apache log4net before 2.0.8 does not disable XML external entities when parsing log4net configuration files. This could allow for XXE-based attacks in applications that accept arbitrary configuration files from users.
References:
https://issues.apache.org/jira/browse/LOG4NET-575
https://lists.apache.org/thread.html/reab1c277c95310bad1038255e0757857b2fbe291411b4fa84552028a%40%3Cdev.logging.apache.org%3E
Discussion:
As far as I can see, we are using version 2.0.8 in all supported Fedora releases and in Epel 7 and 8:
We don't have a package in Epel 6.
https://apps.fedoraproject.org/packages/log4net
---
@Guilherme: you wrote "before 2.0.8", but the Apache issue says "Affected: log4net up to 2.
Bugzilla
CVE-2018-1274 spring-data-commons: Unlimited path depth in PropertyPath.java allow remote attackers to cause a denial of service
bugzilla·2018-04-11·CVSS 7.5
CVE-2018-1274 [HIGH] CVE-2018-1274 spring-data-commons: Unlimited path depth in PropertyPath.java allow remote attackers to cause a denial of service
CVE-2018-1274 spring-data-commons: Unlimited path depth in PropertyPath.java allow remote attackers to cause a denial of service
Spring Data Commons, versions 1.13 to 1.13.10 and 2.0 to 2.0.5, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).
External References:
https://pivotal.io/security/cve-2018-1274
Upstream Issue:
https://jira.spring.io/browse/DATACMNS-1285
Upstream Patches:
https://github.com/spring-projects/spring-data-commons/commit/371f6590c509c72f8e600f3d05e110941607fbad
https://github.com/spring-projects/spring-data-comm
Checkpoint
8th March – Threat Intelligence Report
blogs_checkpoint·2021-03-08
CVE-2021-1285 8th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 8th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 8th March, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
SITA, a communications and IT vendor for 90 percent of the world’s airlines, has been breached in a massive supply-chain attack, compromising frequent-flyer data across many carriers such as United, Singapore Airlines, Lufthansa, and more.
Spirit Airlines has suffered a data breach by “Nefilim” ransomware. A first batch of cus
https://issues.apache.org/jira/browse/LOG4NET-575https://lists.apache.org/thread.html/r00b16ac5e0bbf7009a0d167ed58f3f94d0033b0f4b3e3d5025cc4872%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/r33564de316d4e4ba0fea1d4d079e62cde1ffe64369c1157243d840d9%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/r525cbbd7db0aef4a114cf60de8439aa285decc34904d42a7f14f39c3%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/r6543acafca3e2d24ff4b0c364a91540cb9378977ffa8d37a03ab4b0f%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/r7ab6b6e702f11a6f77b0db2af2d5e5532f56ae4b99b5fe73c5200b6a%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/r9de86a185575e6c5f92e2a70a1d2e2e9514dc4341251577aac8e3866%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/rd2d72a017e238d1f345f9d14e075c81be16fc68a41c9e9ad9e29a732%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/rdbac24c945ca5c69cd5348b5ac023bc625768f653335de146e09ae2d%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/reab1c277c95310bad1038255e0757857b2fbe291411b4fa84552028a%40%3Cdev.logging.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M2U233HVAQDSZ2PRG4XSGDASLY3J6ALH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VKL2LPINAI6BCMXOH4V4HVHGLUXIWOFO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT2DNNSW7C7FNK3MA3SLEUHGW5USYZKE/https://security.netapp.com/advisory/ntap-20220909-0001/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://issues.apache.org/jira/browse/LOG4NET-575https://lists.apache.org/thread.html/r00b16ac5e0bbf7009a0d167ed58f3f94d0033b0f4b3e3d5025cc4872%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/r33564de316d4e4ba0fea1d4d079e62cde1ffe64369c1157243d840d9%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/r525cbbd7db0aef4a114cf60de8439aa285decc34904d42a7f14f39c3%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/r6543acafca3e2d24ff4b0c364a91540cb9378977ffa8d37a03ab4b0f%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/r7ab6b6e702f11a6f77b0db2af2d5e5532f56ae4b99b5fe73c5200b6a%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/r9de86a185575e6c5f92e2a70a1d2e2e9514dc4341251577aac8e3866%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/rd2d72a017e238d1f345f9d14e075c81be16fc68a41c9e9ad9e29a732%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/rdbac24c945ca5c69cd5348b5ac023bc625768f653335de146e09ae2d%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/reab1c277c95310bad1038255e0757857b2fbe291411b4fa84552028a%40%3Cdev.logging.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M2U233HVAQDSZ2PRG4XSGDASLY3J6ALH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VKL2LPINAI6BCMXOH4V4HVHGLUXIWOFO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT2DNNSW7C7FNK3MA3SLEUHGW5USYZKE/https://security.netapp.com/advisory/ntap-20220909-0001/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.html
2020-05-11
Published