CVE-2020-9488
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD
Description
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Affected (101)
Products: Apache: Log4j · Oracle: Communications Application Session Controller, Communications Billing And Revenue Management, Communications Eagle Ftp Table Base Retrieval, Communications Offline Mediation Controller, Communications Services Gatekeeper, Communications Unified Inventory Management, Data Integrator, Enterprise Manager For Peoplesoft, Financial Services Analytical Applications Infrastructure, Financial Services Institutional Performance Analytics, Financial Services Market Risk Measurement And Management, Financial Services Price Creation And Discovery, Financial Services Retail Customer Analytics, Flexcube Core Banking, Flexcube Private Banking, Health Sciences Information Manager, Insurance Insbridge Rating And Underwriting, Insurance Policy Administration J2ee, Insurance Rules Palette, Jd Edwards World Security, Oracle Goldengate Application Adapters, Peoplesoft Enterprise Peopletools, Policy Automation, Policy Automation Connector For Siebel, Policy Automation For Mobile Devices, Primavera Unifier, Retail Advanced Inventory Planning, Retail Assortment Planning, Retail Bulk Data Integration, Retail Customer Management And Segmentation Foundation, Retail Eftlink, Retail Insights Cloud Service Suite, Retail Integration Bus, Retail Order Broker Cloud Service, Retail Predictive Application Server, Retail Xstore Point Of Service, Siebel Apps Marketing, Siebel Ui Framework, Spatial And Graph, Storagetek Acsls, Storagetek Tape Analytics Sw Tool, Utilities Framework, Weblogic Server · Debian: Debian Linux · +1 more
Show all products
Apache: Log4j · Oracle: Communications Application Session Controller, Communications Billing And Revenue Management, Communications Eagle Ftp Table Base Retrieval, Communications Offline Mediation Controller, Communications Services Gatekeeper, Communications Unified Inventory Management, Data Integrator, Enterprise Manager For Peoplesoft, Financial Services Analytical Applications Infrastructure, Financial Services Institutional Performance Analytics, Financial Services Market Risk Measurement And Management, Financial Services Price Creation And Discovery, Financial Services Retail Customer Analytics, Flexcube Core Banking, Flexcube Private Banking, Health Sciences Information Manager, Insurance Insbridge Rating And Underwriting, Insurance Policy Administration J2ee, Insurance Rules Palette, Jd Edwards World Security, Oracle Goldengate Application Adapters, Peoplesoft Enterprise Peopletools, Policy Automation, Policy Automation Connector For Siebel, Policy Automation For Mobile Devices, Primavera Unifier, Retail Advanced Inventory Planning, Retail Assortment Planning, Retail Bulk Data Integration, Retail Customer Management And Segmentation Foundation, Retail Eftlink, Retail Insights Cloud Service Suite, Retail Integration Bus, Retail Order Broker Cloud Service, Retail Predictive Application Server, Retail Xstore Point Of Service, Siebel Apps Marketing, Siebel Ui Framework, Spatial And Graph, Storagetek Acsls, Storagetek Tape Analytics Sw Tool, Utilities Framework, Weblogic Server · Debian: Debian Linux · Qos: Reload4j
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.9m0p1 | |
| Version 12.0.0.3.0 | |
| Version 4.5 | |
| Version 12.0.0.3.0 | |
| Version 7.0 | |
| Version 7.3.0 | |
| Version 12.2.1.3.0 | |
| Version 13.4.1.1 | |
| From 8.0.6.0.0 to 8.1.0.0.0 | |
| Version 8.0.6 | |
| Version 8.0.6 | |
| Version 8.0.6 | |
| Version 8.0.6 | |
| From 11.5.0 to 11.7.0 | |
| Version 12.0.0 | |
| Version 3.0.1 | |
| From 5.0.0.0 to 5.6.0.0 | |
| Version 10.2.0.37 | |
| Version 10.2.0.37 | |
| Version a9.4 | |
| Version 19.1.0.0.0 | |
| Version 8.56 | |
| From 12.2.0 to 12.2.20 | |
| Version 10.4.6 | |
| From 12.2.0 to 12.2.20 | |
| Version 18.8 | |
| Version 14.1 | |
| Version 15.0.3.0 | |
| Version 15.0.3.0 | |
| Version 16.0 | |
| Version 15.0.2 | |
| Version 19.0 | |
| Version 14.1 | |
| Version 16.0 | |
| Version 14.1.3.0 | |
| Version 15.0.4 | |
| Up to 21.9 | |
| Up to 21.2 | |
| Version 12.2.0.1 | |
| Version 8.5.1 | |
| Version 2.3.1 | |
| From 4.3.0.1.0 to 4.3.0.6.0 | |
| Version 10.3.6.0.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
References (98)
Source: security@apache.org
Issue TrackingMitigationPatchVendor Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.