← Back

CVE-2020-9488

nvd nist
Published: Apr 27, 2020Modified: Jun 17, 2026

JSON object

Loading...
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD

Description

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Affected (101)

Products: Apache: Log4j · Oracle: Communications Application Session Controller, Communications Billing And Revenue Management, Communications Eagle Ftp Table Base Retrieval, Communications Offline Mediation Controller, Communications Services Gatekeeper, Communications Unified Inventory Management, Data Integrator, Enterprise Manager For Peoplesoft, Financial Services Analytical Applications Infrastructure, Financial Services Institutional Performance Analytics, Financial Services Market Risk Measurement And Management, Financial Services Price Creation And Discovery, Financial Services Retail Customer Analytics, Flexcube Core Banking, Flexcube Private Banking, Health Sciences Information Manager, Insurance Insbridge Rating And Underwriting, Insurance Policy Administration J2ee, Insurance Rules Palette, Jd Edwards World Security, Oracle Goldengate Application Adapters, Peoplesoft Enterprise Peopletools, Policy Automation, Policy Automation Connector For Siebel, Policy Automation For Mobile Devices, Primavera Unifier, Retail Advanced Inventory Planning, Retail Assortment Planning, Retail Bulk Data Integration, Retail Customer Management And Segmentation Foundation, Retail Eftlink, Retail Insights Cloud Service Suite, Retail Integration Bus, Retail Order Broker Cloud Service, Retail Predictive Application Server, Retail Xstore Point Of Service, Siebel Apps Marketing, Siebel Ui Framework, Spatial And Graph, Storagetek Acsls, Storagetek Tape Analytics Sw Tool, Utilities Framework, Weblogic Server · Debian: Debian Linux · +1 more
Show all products
Apache: Log4j · Oracle: Communications Application Session Controller, Communications Billing And Revenue Management, Communications Eagle Ftp Table Base Retrieval, Communications Offline Mediation Controller, Communications Services Gatekeeper, Communications Unified Inventory Management, Data Integrator, Enterprise Manager For Peoplesoft, Financial Services Analytical Applications Infrastructure, Financial Services Institutional Performance Analytics, Financial Services Market Risk Measurement And Management, Financial Services Price Creation And Discovery, Financial Services Retail Customer Analytics, Flexcube Core Banking, Flexcube Private Banking, Health Sciences Information Manager, Insurance Insbridge Rating And Underwriting, Insurance Policy Administration J2ee, Insurance Rules Palette, Jd Edwards World Security, Oracle Goldengate Application Adapters, Peoplesoft Enterprise Peopletools, Policy Automation, Policy Automation Connector For Siebel, Policy Automation For Mobile Devices, Primavera Unifier, Retail Advanced Inventory Planning, Retail Assortment Planning, Retail Bulk Data Integration, Retail Customer Management And Segmentation Foundation, Retail Eftlink, Retail Insights Cloud Service Suite, Retail Integration Bus, Retail Order Broker Cloud Service, Retail Predictive Application Server, Retail Xstore Point Of Service, Siebel Apps Marketing, Siebel Ui Framework, Spatial And Graph, Storagetek Acsls, Storagetek Tape Analytics Sw Tool, Utilities Framework, Weblogic Server · Debian: Debian Linux · Qos: Reload4j
1 product
Log4j
43 products
Data Integrator
Enterprise Manager For Peoplesoft
Flexcube Core Banking
Flexcube Private Banking
Insurance Rules Palette
Jd Edwards World Security
Peoplesoft Enterprise Peopletools
Policy Automation
Primavera Unifier
Retail Assortment Planning
Retail Bulk Data Integration
Retail Eftlink
Retail Integration Bus
Retail Order Broker Cloud Service
Retail Xstore Point Of Service
Siebel Apps Marketing
Siebel Ui Framework
Spatial And Graph
Storagetek Acsls
Storagetek Tape Analytics Sw Tool
Utilities Framework
Weblogic Server
1 product
Debian Linux
1 product
Reload4j
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 2.0 to 2.3.2
From 2.13.0 to 2.13.2
From 2.4 to 2.12.3
Configuration B
94 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.9m0p1
Oracle
Version 12.0.0.3.0
Version 7.5.0.23.0
Version 4.5
Version 12.0.0.3.0
Version 7.0
Oracle
Version 7.3.0
Version 7.4.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 13.4.1.1
From 8.0.6.0.0 to 8.1.0.0.0
Oracle
Version 8.0.6
Version 8.1.0
Version 8.7.0
Oracle
Version 8.0.6
Version 8.0.8
Version 8.1.0
Oracle
Version 8.0.6
Version 8.0.7
Version 8.0.6
Oracle
From 11.5.0 to 11.7.0
Version 5.2.0
Oracle
Version 12.0.0
Version 12.1.0
Version 3.0.1
Oracle
From 5.0.0.0 to 5.6.0.0
Version 5.6.1.0
Oracle
Version 10.2.0.37
Version 10.2.4.12
Version 11.0.2.25
Version 11.1.0.15
Version 11.2.0.26
Oracle
Version 10.2.0.37
Version 10.2.4.12
Version 11.0.2.25
Version 11.1.0.15
Version 11.2.0.26
Version a9.4
Version 19.1.0.0.0
Oracle
Version 8.56
Version 8.57
Version 8.58
From 12.2.0 to 12.2.20
Version 10.4.6
From 12.2.0 to 12.2.20
Oracle
Version 18.8
Version 19.12
Version 14.1
Oracle
Version 15.0.3.0
Version 16.0.3.0
Oracle
Version 15.0.3.0
Version 16.0.3.0
Oracle
Version 16.0
Version 17.0
Version 18.0
Version 19.0
Oracle
Version 15.0.2
Version 16.0.3
Version 17.0.2
Version 18.0.1
Version 19.0.1
Version 19.0
Oracle
Version 14.1
Version 15.0
Version 16.0
Oracle
Version 16.0
Version 18.0
Version 19.0
Version 19.1
Version 19.2
Version 19.3
Oracle
Version 14.1.3.0
Version 15.0.3.0
Version 16.0.3.0
Oracle
Version 15.0.4
Version 16.0.6
Version 17.0.4
Version 18.0.3
Version 19.0.2
Up to 21.9
Up to 21.2
Oracle
Version 12.2.0.1
Version 18c
Version 19c
Version 8.5.1
Version 2.3.1
Oracle
From 4.3.0.1.0 to 4.3.0.6.0
Version 2.2.0.0.0
Version 4.2.0.2.0
Version 4.2.0.3.0
Version 4.4.0.0.0
Version 4.4.0.2.0
Version 10.3.6.0.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Version 9.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.2.18.3

References (98)

Source: security@apache.org
Issue TrackingMitigationPatchVendor Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.