CVE-2020-9488
Last modified
CVE-2020-9488 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. EPSS estimates a 7.81% chance of exploitation in the next 30 days.
Description
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Log4j | >= 2.0, < 2.3.2 |
| Apache | Log4j | >= 2.4, < 2.12.3 |
| Apache | Log4j | >= 2.13.0, < 2.13.2 |
| Oracle | Communications Application Session Controller | 3.9m0p1 |
| Oracle | Communications Billing And Revenue Management | 7.5.0.23.0 |
| Oracle | Communications Billing And Revenue Management | 12.0.0.3.0 |
| Oracle | Communications Eagle Ftp Table Base Retrieval | 4.5 |
| Oracle | Communications Offline Mediation Controller | 12.0.0.3.0 |
| Oracle | Communications Services Gatekeeper | 7.0 |
| Oracle | Communications Unified Inventory Management | 7.3.0 |
| Oracle | Communications Unified Inventory Management | 7.4.0 |
| Oracle | Data Integrator | 12.2.1.3.0 |
| Oracle | Data Integrator | 12.2.1.4.0 |
| Oracle | Enterprise Manager For Peoplesoft | 13.4.1.1 |
| Oracle | Financial Services Analytical Applications Infrastructure | >= 8.0.6.0.0, <= 8.1.0.0.0 |
| Oracle | Financial Services Institutional Performance Analytics | 8.0.6 |
| Oracle | Financial Services Institutional Performance Analytics | 8.1.0 |
| Oracle | Financial Services Institutional Performance Analytics | 8.7.0 |
| Oracle | Financial Services Market Risk Measurement And Management | 8.0.6 |
| Oracle | Financial Services Market Risk Measurement And Management | 8.0.8 |
| Oracle | Financial Services Market Risk Measurement And Management | 8.1.0 |
| Oracle | Financial Services Price Creation And Discovery | 8.0.6 |
| Oracle | Financial Services Price Creation And Discovery | 8.0.7 |
| Oracle | Financial Services Retail Customer Analytics | 8.0.6 |
| Oracle | Flexcube Core Banking | >= 11.5.0, <= 11.7.0 |
| Oracle | Flexcube Core Banking | 5.2.0 |
| Oracle | Flexcube Private Banking | 12.0.0 |
| Oracle | Flexcube Private Banking | 12.1.0 |
| Oracle | Health Sciences Information Manager | 3.0.1 |
| Oracle | Insurance Insbridge Rating And Underwriting | >= 5.0.0.0, <= 5.6.0.0 |
| Oracle | Insurance Insbridge Rating And Underwriting | 5.6.1.0 |
| Oracle | Insurance Policy Administration J2ee | 10.2.0.37 |
| Oracle | Insurance Policy Administration J2ee | 10.2.4.12 |
| Oracle | Insurance Policy Administration J2ee | 11.0.2.25 |
| Oracle | Insurance Policy Administration J2ee | 11.1.0.15 |
| Oracle | Insurance Policy Administration J2ee | 11.2.0.26 |
| Oracle | Insurance Rules Palette | 10.2.0.37 |
| Oracle | Insurance Rules Palette | 10.2.4.12 |
| Oracle | Insurance Rules Palette | 11.0.2.25 |
| Oracle | Insurance Rules Palette | 11.1.0.15 |
| Oracle | Insurance Rules Palette | 11.2.0.26 |
| Oracle | Jd Edwards World Security | a9.4 |
| Oracle | Oracle Goldengate Application Adapters | 19.1.0.0.0 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.56 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.57 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.58 |
| Oracle | Policy Automation | >= 12.2.0, <= 12.2.20 |
| Oracle | Policy Automation Connector For Siebel | 10.4.6 |
| Oracle | Policy Automation For Mobile Devices | >= 12.2.0, <= 12.2.20 |
| Oracle | Primavera Unifier | 18.8 |
Showing 50 of 101 affected configurations. See NVD for the full list.
References
- https://issues.apache.org/jira/browse/LOG4J2-2819Issue Tracking, Mitigation, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00017.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200504-0003/Third Party Advisory
- https://www.debian.org/security/2021/dsa-5020Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://issues.apache.org/jira/browse/LOG4J2-2819Issue Tracking, Mitigation, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00017.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200504-0003/Third Party Advisory
- https://www.debian.org/security/2021/dsa-5020Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-9488?
How severe is CVE-2020-9488?
How do I fix CVE-2020-9488?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-9482If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mecha…6.5
- CVE-2020-9483**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking sto…7.5
- CVE-2020-9484When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.…7
- CVE-2020-9485An issue was found in Apache Airflow versions 1.10.10 and be…6.1
- CVE-2020-9486In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless executio…7.5
- CVE-2020-9487In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one…7.5
- CVE-2020-9489A carefully crafted or corrupt file may trigger a System.exi…5.5
- CVE-2020-9490Apache HTTP Server versions 2.4.20 to 2.4.43. A specially cr…7.5
- CVE-2020-9491In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were pro…7.5
- CVE-2020-9492In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and …8.8
- CVE-2020-9493A deserialization flaw was found in Apache Chainsaw versions…9.8
- CVE-2020-9494Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8…7.5
Are you affected by CVE-2020-9488?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
