Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-9488


Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1


Published

2020-04-27T16:15:12.897

Last Modified

2024-11-21T05:40:45.037

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.7 (LOW)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache log4j < 2.3.2 Yes
Application apache log4j < 2.12.3 Yes
Application apache log4j < 2.13.2 Yes
Application oracle communications_application_session_controller 3.9m0p1 Yes
Application oracle communications_billing_and_revenue_management 7.5.0.23.0 Yes
Application oracle communications_billing_and_revenue_management 12.0.0.3.0 Yes
Application oracle communications_eagle_ftp_table_base_retrieval 4.5 Yes
Application oracle communications_offline_mediation_controller 12.0.0.3.0 Yes
Application oracle communications_services_gatekeeper 7.0 Yes
Application oracle communications_unified_inventory_management 7.3.0 Yes
Application oracle communications_unified_inventory_management 7.4.0 Yes
Application oracle data_integrator 12.2.1.3.0 Yes
Application oracle data_integrator 12.2.1.4.0 Yes
Application oracle enterprise_manager_for_peoplesoft 13.4.1.1 Yes
Application oracle financial_services_analytical_applications_infrastructure ≤ 8.1.0.0.0 Yes
Application oracle financial_services_institutional_performance_analytics 8.0.6 Yes
Application oracle financial_services_institutional_performance_analytics 8.1.0 Yes
Application oracle financial_services_institutional_performance_analytics 8.7.0 Yes
Application oracle financial_services_market_risk_measurement_and_management 8.0.6 Yes
Application oracle financial_services_market_risk_measurement_and_management 8.0.8 Yes
Application oracle financial_services_market_risk_measurement_and_management 8.1.0 Yes
Application oracle financial_services_price_creation_and_discovery 8.0.6 Yes
Application oracle financial_services_price_creation_and_discovery 8.0.7 Yes
Application oracle financial_services_retail_customer_analytics 8.0.6 Yes
Application oracle flexcube_core_banking ≤ 11.7.0 Yes
Application oracle flexcube_core_banking 5.2.0 Yes
Application oracle flexcube_private_banking 12.0.0 Yes
Application oracle flexcube_private_banking 12.1.0 Yes
Application oracle health_sciences_information_manager 3.0.1 Yes
Application oracle insurance_insbridge_rating_and_underwriting ≤ 5.6.0.0 Yes
Application oracle insurance_insbridge_rating_and_underwriting 5.6.1.0 Yes
Application oracle insurance_policy_administration_j2ee 10.2.0.37 Yes
Application oracle insurance_policy_administration_j2ee 10.2.4.12 Yes
Application oracle insurance_policy_administration_j2ee 11.0.2.25 Yes
Application oracle insurance_policy_administration_j2ee 11.1.0.15 Yes
Application oracle insurance_policy_administration_j2ee 11.2.0.26 Yes
Application oracle insurance_rules_palette 10.2.0.37 Yes
Application oracle insurance_rules_palette 10.2.4.12 Yes
Application oracle insurance_rules_palette 11.0.2.25 Yes
Application oracle insurance_rules_palette 11.1.0.15 Yes
Application oracle insurance_rules_palette 11.2.0.26 Yes
Application oracle jd_edwards_world_security a9.4 Yes
Application oracle oracle_goldengate_application_adapters 19.1.0.0.0 Yes
Application oracle peoplesoft_enterprise_peopletools 8.56 Yes
Application oracle peoplesoft_enterprise_peopletools 8.57 Yes
Application oracle peoplesoft_enterprise_peopletools 8.58 Yes
Application oracle policy_automation ≤ 12.2.20 Yes
Application oracle policy_automation_connector_for_siebel 10.4.6 Yes
Application oracle policy_automation_for_mobile_devices ≤ 12.2.20 Yes
Application oracle primavera_unifier 18.8 Yes
Application oracle primavera_unifier 19.12 Yes
Application oracle retail_advanced_inventory_planning 14.1 Yes
Application oracle retail_assortment_planning 15.0.3.0 Yes
Application oracle retail_assortment_planning 16.0.3.0 Yes
Application oracle retail_bulk_data_integration 15.0.3.0 Yes
Application oracle retail_bulk_data_integration 16.0.3.0 Yes
Application oracle retail_customer_management_and_segmentation_foundation 16.0 Yes
Application oracle retail_customer_management_and_segmentation_foundation 17.0 Yes
Application oracle retail_customer_management_and_segmentation_foundation 18.0 Yes
Application oracle retail_customer_management_and_segmentation_foundation 19.0 Yes
Application oracle retail_eftlink 15.0.2 Yes
Application oracle retail_eftlink 16.0.3 Yes
Application oracle retail_eftlink 17.0.2 Yes
Application oracle retail_eftlink 18.0.1 Yes
Application oracle retail_eftlink 19.0.1 Yes
Application oracle retail_insights_cloud_service_suite 19.0 Yes
Application oracle retail_integration_bus 14.1 Yes
Application oracle retail_integration_bus 15.0 Yes
Application oracle retail_integration_bus 16.0 Yes
Application oracle retail_order_broker_cloud_service 16.0 Yes
Application oracle retail_order_broker_cloud_service 18.0 Yes
Application oracle retail_order_broker_cloud_service 19.0 Yes
Application oracle retail_order_broker_cloud_service 19.1 Yes
Application oracle retail_order_broker_cloud_service 19.2 Yes
Application oracle retail_order_broker_cloud_service 19.3 Yes
Application oracle retail_predictive_application_server 14.1.3.0 Yes
Application oracle retail_predictive_application_server 15.0.3.0 Yes
Application oracle retail_predictive_application_server 16.0.3.0 Yes
Application oracle retail_xstore_point_of_service 15.0.4 Yes
Application oracle retail_xstore_point_of_service 16.0.6 Yes
Application oracle retail_xstore_point_of_service 17.0.4 Yes
Application oracle retail_xstore_point_of_service 18.0.3 Yes
Application oracle retail_xstore_point_of_service 19.0.2 Yes
Application oracle siebel_apps_-_marketing ≤ 21.9 Yes
Application oracle siebel_ui_framework ≤ 21.2 Yes
Application oracle spatial_and_graph 12.2.0.1 Yes
Application oracle spatial_and_graph 18c Yes
Application oracle spatial_and_graph 19c Yes
Application oracle storagetek_acsls 8.5.1 Yes
Application oracle storagetek_tape_analytics_sw_tool 2.3.1 Yes
Application oracle utilities_framework ≤ 4.3.0.6.0 Yes
Application oracle utilities_framework 2.2.0.0.0 Yes
Application oracle utilities_framework 4.2.0.2.0 Yes
Application oracle utilities_framework 4.2.0.3.0 Yes
Application oracle utilities_framework 4.4.0.0.0 Yes
Application oracle utilities_framework 4.4.0.2.0 Yes
Application oracle weblogic_server 10.3.6.0.0 Yes
Operating System debian debian_linux 9.0 Yes
Operating System debian debian_linux 10.0 Yes
Operating System debian debian_linux 11.0 Yes
Application qos reload4j < 1.2.18.3 Yes

References