Vulnerability Details CVE-2018-1288
In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 78.7%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 5.5
Products affected by CVE-2018-1288
-
cpe:2.3:a:apache:kafka:0.10.0.0
-
cpe:2.3:a:apache:kafka:0.10.0.1
-
cpe:2.3:a:apache:kafka:0.10.1.0
-
cpe:2.3:a:apache:kafka:0.10.1.1
-
cpe:2.3:a:apache:kafka:0.10.2.0
-
cpe:2.3:a:apache:kafka:0.10.2.1
-
cpe:2.3:a:apache:kafka:0.11.0.0
-
cpe:2.3:a:apache:kafka:0.11.0.1
-
cpe:2.3:a:apache:kafka:0.11.0.2
-
cpe:2.3:a:apache:kafka:0.9.0.1
-
cpe:2.3:a:apache:kafka:1.0.0
-
cpe:2.3:a:oracle:database:11.2.0.4
-
cpe:2.3:a:oracle:database:12.1.0.2
-
cpe:2.3:a:oracle:database:12.2.0.1
-
cpe:2.3:a:oracle:database:18c
-
cpe:2.3:a:oracle:database:19c
-
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:19.12.0.0
-
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:19.12.1.0
-
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:19.12.2.0
-
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:19.12.3.0
-
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:19.12.4.0
-
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:19.12.5.0
-
cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:19.12.6.0
-
cpe:2.3:a:oracle:timesten_in-memory_database:-
-
cpe:2.3:a:oracle:timesten_in-memory_database:11.2.2.8.27
-
cpe:2.3:a:oracle:timesten_in-memory_database:11.2.2.8.49
-
cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:1.0