CVE-2020-9488
Last modified
CVE-2020-9488 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. EPSS estimates a 7.81% chance of exploitation in the next 30 days.
Description
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Log4j | >= 2.0, < 2.3.2 |
| Apache | Log4j | >= 2.4, < 2.12.3 |
| Apache | Log4j | >= 2.13.0, < 2.13.2 |
| Oracle | Communications Application Session Controller | 3.9m0p1 |
| Oracle | Communications Billing And Revenue Management | 7.5.0.23.0 |
| Oracle | Communications Billing And Revenue Management | 12.0.0.3.0 |
| Oracle | Communications Eagle Ftp Table Base Retrieval | 4.5 |
| Oracle | Communications Offline Mediation Controller | 12.0.0.3.0 |
| Oracle | Communications Services Gatekeeper | 7.0 |
| Oracle | Communications Unified Inventory Management | 7.3.0 |
| Oracle | Communications Unified Inventory Management | 7.4.0 |
| Oracle | Data Integrator | 12.2.1.3.0 |
| Oracle | Data Integrator | 12.2.1.4.0 |
| Oracle | Enterprise Manager For Peoplesoft | 13.4.1.1 |
| Oracle | Financial Services Analytical Applications Infrastructure | >= 8.0.6.0.0, <= 8.1.0.0.0 |
| Oracle | Financial Services Institutional Performance Analytics | 8.0.6 |
| Oracle | Financial Services Institutional Performance Analytics | 8.1.0 |
| Oracle | Financial Services Institutional Performance Analytics | 8.7.0 |
| Oracle | Financial Services Market Risk Measurement And Management | 8.0.6 |
| Oracle | Financial Services Market Risk Measurement And Management | 8.0.8 |
| Oracle | Financial Services Market Risk Measurement And Management | 8.1.0 |
| Oracle | Financial Services Price Creation And Discovery | 8.0.6 |
| Oracle | Financial Services Price Creation And Discovery | 8.0.7 |
| Oracle | Financial Services Retail Customer Analytics | 8.0.6 |
| Oracle | Flexcube Core Banking | >= 11.5.0, <= 11.7.0 |
| Oracle | Flexcube Core Banking | 5.2.0 |
| Oracle | Flexcube Private Banking | 12.0.0 |
| Oracle | Flexcube Private Banking | 12.1.0 |
| Oracle | Health Sciences Information Manager | 3.0.1 |
| Oracle | Insurance Insbridge Rating And Underwriting | >= 5.0.0.0, <= 5.6.0.0 |
| Oracle | Insurance Insbridge Rating And Underwriting | 5.6.1.0 |
| Oracle | Insurance Policy Administration J2ee | 10.2.0.37 |
| Oracle | Insurance Policy Administration J2ee | 10.2.4.12 |
| Oracle | Insurance Policy Administration J2ee | 11.0.2.25 |
| Oracle | Insurance Policy Administration J2ee | 11.1.0.15 |
| Oracle | Insurance Policy Administration J2ee | 11.2.0.26 |
| Oracle | Insurance Rules Palette | 10.2.0.37 |
| Oracle | Insurance Rules Palette | 10.2.4.12 |
| Oracle | Insurance Rules Palette | 11.0.2.25 |
| Oracle | Insurance Rules Palette | 11.1.0.15 |
| Oracle | Insurance Rules Palette | 11.2.0.26 |
| Oracle | Jd Edwards World Security | a9.4 |
| Oracle | Oracle Goldengate Application Adapters | 19.1.0.0.0 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.56 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.57 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.58 |
| Oracle | Policy Automation | >= 12.2.0, <= 12.2.20 |
| Oracle | Policy Automation Connector For Siebel | 10.4.6 |
| Oracle | Policy Automation For Mobile Devices | >= 12.2.0, <= 12.2.20 |
| Oracle | Primavera Unifier | 18.8 |
Showing 50 of 101 affected configurations. See NVD for the full list.
References
- https://issues.apache.org/jira/browse/LOG4J2-2819Issue Tracking, Mitigation, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00017.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200504-0003/Third Party Advisory
- https://www.debian.org/security/2021/dsa-5020Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://issues.apache.org/jira/browse/LOG4J2-2819Issue Tracking, Mitigation, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00017.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200504-0003/Third Party Advisory
- https://www.debian.org/security/2021/dsa-5020Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-9488?
How severe is CVE-2020-9488?
How do I fix CVE-2020-9488?
Are you affected by CVE-2020-9488?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
