CVE-2020-9488

Published Apr 27, 2020

Last updated 9 days ago

Overview

Description
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Source
security@apache.org
NVD status
Modified
Products
log4j, communications_application_session_controller, communications_billing_and_revenue_management, communications_eagle_ftp_table_base_retrieval, communications_offline_mediation_controller, communications_services_gatekeeper, communications_unified_inventory_management, data_integrator, enterprise_manager_for_peoplesoft, financial_services_analytical_applications_infrastructure, financial_services_institutional_performance_analytics, financial_services_market_risk_measurement_and_management, financial_services_price_creation_and_discovery, financial_services_retail_customer_analytics, flexcube_core_banking, flexcube_private_banking, health_sciences_information_manager, insurance_insbridge_rating_and_underwriting, insurance_policy_administration_j2ee, insurance_rules_palette, jd_edwards_world_security, oracle_goldengate_application_adapters, peoplesoft_enterprise_peopletools, policy_automation, policy_automation_connector_for_siebel, policy_automation_for_mobile_devices, primavera_unifier, retail_advanced_inventory_planning, retail_assortment_planning, retail_bulk_data_integration, retail_customer_management_and_segmentation_foundation, retail_eftlink, retail_insights_cloud_service_suite, retail_integration_bus, retail_order_broker_cloud_service, retail_predictive_application_server, retail_xstore_point_of_service, siebel_apps_-_marketing, siebel_ui_framework, spatial_and_graph, storagetek_acsls, storagetek_tape_analytics_sw_tool, utilities_framework, weblogic_server, debian_linux, reload4j

Risk scores

CVSS 3.1

Type
Primary
Base score
3.7
Impact score
1.4
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity
LOW

CVSS 2.0

Type
Primary
Base score
4.3
Impact score
2.9
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:P/I:N/A:N

Weaknesses

nvd@nist.gov
CWE-295
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-295

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.