cbcvebase.
CVE-2020-9488
published 2020-04-27

CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a…

PriorityP422low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
8.10%
94.2th percentile
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Affected

105 ranges· showing 25
VendorProductVersion rangeFixed in
apacheapache_log4j
apacheapache_log4j>= log4j-core < 2.12.32.12.3
apachelog4j>= 2.0 < 2.3.22.3.2
apachelog4j>= 2.13.0 < 2.13.22.13.2
apachelog4j>= 2.4 < 2.12.32.12.3
apachelogging
debianapache-log4j2< apache-log4j2 2.13.3-1 (bookworm)apache-log4j2 2.13.3-1 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
oraclecommunications_application_session_controller
oraclecommunications_billing_and_revenue_management
oraclecommunications_billing_and_revenue_management
oraclecommunications_eagle_ftp_table_base_retrieval
oraclecommunications_offline_mediation_controller
oraclecommunications_services_gatekeeper
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oracledata_integrator
oracledata_integrator
oracleenterprise_manager_for_peoplesoft
oraclefinancial_services_analytical_applications_infrastructure8.0.6.0.0 – 8.1.0.0.0
oraclefinancial_services_institutional_performance_analytics
oraclefinancial_services_institutional_performance_analytics
oraclefinancial_services_institutional_performance_analytics

CVSS provenance

nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv3.7LOW
vendor_apache3.7LOW
vendor_debian3.7LOW
vendor_oracle3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.