Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-1285

44
FAUCET Score

CVE-2018-1285 is a critical XML External Entity (XXE) vulnerability affecting Apache log4net versions prior to 2.0.10, impacting products from Apache, FedoraProject, NetApp, and Oracle. This flaw allows attackers to perform XXE-based attacks by providing malicious log4net configuration files, leading to potential compromise of confidentiality, integrity, and availability. With a CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 97/100, it presents a significant risk. While there is no known active exploitation or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion, indicating awareness within the cybersecurity landscape.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.0.10CPE matchmatch criteria
cpe:2.3:a:apache:log4net:*:*:*:*:*:*:*:*
30CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
32CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
13.3.0.1CPE matchmatch criteria
cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
17.37%
Probability of exploitation in next 30 days
EPSS Percentile
96.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.1737 is in the 93rd percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

nugetpatch availablevia ghsa
Product: log4netFixed in: 2.0.10
oraclepatch availablevia nvd_reference
View patch
cephvendor investigatingvia llm_extracted
d-linkvendor investigatingvia llm_extracted
humansignalvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
m2teamvendor investigatingvia llm_extracted
roundcubevendor investigatingvia llm_extracted

Vendor Advisories (13)

roundcubellm-roundcube-16ec652a2022483fCRITICAL

Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability

Mar 23, 2022
humansignalllm-humansignal-4709faede3e2fb07CRITICAL

Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability

Mar 23, 2022
hyperledgerllm-hyperledger-e9f17122d3cdc3acCRITICAL

Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability

Mar 23, 2022
d-linkllm-d-link-2f5ecc955d6c11f7CRITICAL

Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability

Mar 23, 2022
cephllm-ceph-f9b569f719561e24CRITICAL

Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability

Mar 23, 2022
m2teamllm-m2team-0c0594601646ee33CRITICAL

Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability

Mar 23, 2022
m2teamllm-m2team-e442d1defd93d530CRITICAL

Improper Restriction of XML External Entity Reference in BVMS

Mar 16, 2022
hyperledgerllm-hyperledger-adf01ac0d86c2a72CRITICAL

Improper Restriction of XML External Entity Reference in BVMS

Mar 16, 2022
roundcubellm-roundcube-70a1fd632caca387CRITICAL

Improper Restriction of XML External Entity Reference in BVMS

Mar 16, 2022
cephllm-ceph-9f9198a155ba6bbfCRITICAL

Improper Restriction of XML External Entity Reference in BVMS

Mar 16, 2022
humansignalllm-humansignal-eb750a94274b4835CRITICAL

Improper Restriction of XML External Entity Reference in BVMS

Mar 16, 2022
d-linkllm-d-link-23f020358797e37bCRITICAL

Improper Restriction of XML External Entity Reference in BVMS

Mar 16, 2022
nugetGHSA-2cwj-8chv-9pp9critical

XML External Entity attack in log4net

Jan 29, 2021

References

issues.apache.org / jira/browse/LOG4NET-575
Issue TrackingVendor Advisory
lists.apache.org / thread.html/r00b16ac5e0bbf7009a0d167ed58f3f94d0033b0f4b3e3d5025cc4872%40%3Cdev.logging.apache.org%3E
lists.apache.org / thread.html/r33564de316d4e4ba0fea1d4d079e62cde1ffe64369c1157243d840d9%40%3Cdev.logging.apache.org%3E
lists.apache.org / thread.html/r525cbbd7db0aef4a114cf60de8439aa285decc34904d42a7f14f39c3%40%3Cdev.logging.apache.org%3E
lists.apache.org / thread.html/r6543acafca3e2d24ff4b0c364a91540cb9378977ffa8d37a03ab4b0f%40%3Cdev.logging.apache.org%3E
lists.apache.org / thread.html/r7ab6b6e702f11a6f77b0db2af2d5e5532f56ae4b99b5fe73c5200b6a%40%3Cdev.logging.apache.org%3E
lists.apache.org / thread.html/r9de86a185575e6c5f92e2a70a1d2e2e9514dc4341251577aac8e3866%40%3Cdev.logging.apache.org%3E
lists.apache.org / thread.html/rd2d72a017e238d1f345f9d14e075c81be16fc68a41c9e9ad9e29a732%40%3Cdev.logging.apache.org%3E
lists.apache.org / thread.html/rdbac24c945ca5c69cd5348b5ac023bc625768f653335de146e09ae2d%40%3Cdev.logging.apache.org%3E
lists.apache.org / thread.html/reab1c277c95310bad1038255e0757857b2fbe291411b4fa84552028a%40%3Cdev.logging.apache.org%3E
Mailing ListVendor Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/M2U233HVAQDSZ2PRG4XSGDASLY3J6ALH
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/VKL2LPINAI6BCMXOH4V4HVHGLUXIWOFO
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/VT2DNNSW7C7FNK3MA3SLEUHGW5USYZKE
security.netapp.com / advisory/ntap-20220909-0001
Third Party Advisory
oracle.com / security-alerts/cpuApr2021.html
Third Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2021.html
Third Party Advisory