- What: Vulnerability in SLF4J allowing code execution
- Impact: Remote attackers can execute arbitrary code
[WID-SEC-2023-3225] SLF4J: Schwachstelle ermöglicht Codeausführung CVSS Base Score 7.3 (hoch) CVSS Temporal Score 6.4 (mittel) Remoteangriff ja Datum 26.03.2018 Stand UPDATE 03.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges Windows Produktbeschreibung Simple Logging Facade for Java (SLF4J) (SLF4J) bietet eine Java Logging API. Produkte UPDATE 02.08.2026 Oracle Linux UPDATE 25.01.2026 Dell Data Protection Advisor <19.12 UPDATE 27.12.2023 NetApp ActiveIQ Unified Manager for Linux NetApp ActiveIQ Unified Manager for VMware vSphere NetApp ActiveIQ Unified Manager for Microsoft Windows UPDATE 19.06.2018 SUSE Linux UPDATE 27.03.2018 Open Source CentOS 26.03.2018 Oracle Linux 7 Red Hat Enterprise Linux 7 Open Source SLF4J Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in SLF4J ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben