Versio.io

CVE-2020-9488

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 27-04-2020 06:15
Last modified: - 12-05-2022 05:00
Total changes: - 25

Description

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
High
Attack complexity
Network
Attack vector
None
Availability
Low
Confidentiality
None
Integrity
None
Privileges required
Unchanged
Scope
None
User interaction
3.7
Base score
2.2
1.4
Exploitability score
Impact score
 

Verification logic

OR
OR
vendor=apache AND product=log4j AND versionStartIncluding=2.4 AND versionEndExcluding=2.12.3
vendor=apache AND product=log4j AND versionStartIncluding=2.13.0 AND versionEndExcluding=2.13.2
vendor=apache AND product=log4j AND versionStartIncluding=2.0 AND versionEndExcluding=2.3.2
OR
vendor=oracle AND product=flexcube_private_banking AND version=12.1.0
vendor=oracle AND product=retail_integration_bus AND version=14.1
vendor=oracle AND product=flexcube_private_banking AND version=12.0.0
vendor=oracle AND product=flexcube_core_banking AND version=5.2.0
vendor=oracle AND product=retail_integration_bus AND version=15.0
vendor=oracle AND product=peoplesoft_enterprise_peopletools AND version=8.56
vendor=oracle AND product=weblogic_server AND version=10.3.6.0.0
vendor=oracle AND product=utilities_framework AND version=4.2.0.3.0
vendor=oracle AND product=utilities_framework AND version=4.2.0.2.0
vendor=oracle AND product=utilities_framework AND version=2.2.0.0.0
vendor=oracle AND product=communications_billing_and_revenue_management AND version=12.0.0.3.0
vendor=oracle AND product=communications_unified_inventory_management AND version=7.4.0
vendor=oracle AND product=data_integrator AND version=12.2.1.3.0
vendor=oracle AND product=financial_services_analytical_applications_infrastructure AND versionEndIncluding=8.1.0.0.0 AND versionStartIncluding=8.0.6.0.0
vendor=oracle AND product=financial_services_market_risk_measurement_and_management AND version=8.0.6
vendor=oracle AND product=financial_services_price_creation_and_discovery AND version=8.0.7
vendor=oracle AND product=jd_edwards_world_security AND version=a9.4
vendor=oracle AND product=peoplesoft_enterprise_peopletools AND version=8.57
vendor=oracle AND product=peoplesoft_enterprise_peopletools AND version=8.58
vendor=oracle AND product=policy_automation_connector_for_siebel AND version=10.4.6
vendor=oracle AND product=primavera_unifier AND version=18.8
vendor=oracle AND product=primavera_unifier AND version=19.12
vendor=oracle AND product=retail_customer_management_and_segmentation_foundation AND version=16.0
vendor=oracle AND product=retail_customer_management_and_segmentation_foundation AND version=17.0
vendor=oracle AND product=retail_customer_management_and_segmentation_foundation AND version=18.0
vendor=oracle AND product=retail_customer_management_and_segmentation_foundation AND version=19.0
vendor=oracle AND product=retail_integration_bus AND version=16.0
vendor=oracle AND product=utilities_framework AND versionEndIncluding=4.3.0.6.0 AND versionStartIncluding=4.3.0.1.0
vendor=oracle AND product=utilities_framework AND version=4.4.0.0.0
vendor=oracle AND product=utilities_framework AND version=4.4.0.2.0
vendor=oracle AND product=communications_application_session_controller AND version=3.9m0p1
vendor=oracle AND product=communications_billing_and_revenue_management AND version=7.5.0.23.0
vendor=oracle AND product=communications_offline_mediation_controller AND version=12.0.0.3.0
vendor=oracle AND product=communications_unified_inventory_management AND version=7.3.0
vendor=oracle AND product=enterprise_manager_for_peoplesoft AND version=13.4.1.1
vendor=oracle AND product=financial_services_institutional_performance_analytics AND version=8.0.6
vendor=oracle AND product=financial_services_institutional_performance_analytics AND version=8.1.0
vendor=oracle AND product=financial_services_institutional_performance_analytics AND version=8.7.0
vendor=oracle AND product=financial_services_market_risk_measurement_and_management AND version=8.0.8
vendor=oracle AND product=financial_services_market_risk_measurement_and_management AND version=8.1.0
vendor=oracle AND product=financial_services_price_creation_and_discovery AND version=8.0.6
vendor=oracle AND product=financial_services_retail_customer_analytics AND version=8.0.6
vendor=oracle AND product=flexcube_core_banking AND versionEndIncluding=11.7.0 AND versionStartIncluding=11.5.0
vendor=oracle AND product=insurance_insbridge_rating_and_underwriting AND versionEndIncluding=5.6.0.0 AND versionStartIncluding=5.0.0.0
vendor=oracle AND product=insurance_insbridge_rating_and_underwriting AND version=5.6.1.0
vendor=oracle AND product=insurance_policy_administration_j2ee AND version=10.2.0.37
vendor=oracle AND product=insurance_policy_administration_j2ee AND version=10.2.4.12
vendor=oracle AND product=insurance_policy_administration_j2ee AND version=11.0.2.25
vendor=oracle AND product=insurance_policy_administration_j2ee AND version=11.1.0.15
vendor=oracle AND product=insurance_rules_palette AND version=10.2.0.37
vendor=oracle AND product=insurance_rules_palette AND version=10.2.4.12
vendor=oracle AND product=insurance_rules_palette AND version=11.0.2.25
vendor=oracle AND product=insurance_rules_palette AND version=11.1.0.15
vendor=oracle AND product=insurance_rules_palette AND version=11.2.0.26
vendor=oracle AND product=policy_automation AND versionEndIncluding=12.2.20 AND versionStartIncluding=12.2.0
vendor=oracle AND product=policy_automation_for_mobile_devices AND versionEndIncluding=12.2.20 AND versionStartIncluding=12.2.0
vendor=oracle AND product=retail_advanced_inventory_planning AND version=14.1
vendor=oracle AND product=retail_assortment_planning AND version=15.0.3.0
vendor=oracle AND product=retail_assortment_planning AND version=16.0.3.0
vendor=oracle AND product=retail_bulk_data_integration AND version=15.0.3.0
vendor=oracle AND product=retail_bulk_data_integration AND version=16.0.3.0
vendor=oracle AND product=retail_order_broker_cloud_service AND version=16.0
vendor=oracle AND product=retail_order_broker_cloud_service AND version=18.0
vendor=oracle AND product=retail_order_broker_cloud_service AND version=19.0
vendor=oracle AND product=retail_order_broker_cloud_service AND version=19.1
vendor=oracle AND product=retail_order_broker_cloud_service AND version=19.3
vendor=oracle AND product=retail_predictive_application_server AND version=14.1.3.0
vendor=oracle AND product=retail_predictive_application_server AND version=15.0.3.0
vendor=oracle AND product=spatial_and_graph AND version=18c
vendor=oracle AND product=spatial_and_graph AND version=19c
vendor=oracle AND product=communications_eagle_ftp_table_base_retrieval AND version=4.5
vendor=oracle AND product=communications_services_gatekeeper AND version=7.0
vendor=oracle AND product=data_integrator AND version=12.2.1.4.0
vendor=oracle AND product=health_sciences_information_manager AND version=3.0.1
vendor=oracle AND product=insurance_policy_administration_j2ee AND version=11.2.0.26
vendor=oracle AND product=oracle_goldengate_application_adapters AND version=19.1.0.0.0
vendor=oracle AND product=retail_eftlink AND version=15.0.2
vendor=oracle AND product=retail_eftlink AND version=16.0.3
vendor=oracle AND product=retail_eftlink AND version=17.0.2
vendor=oracle AND product=retail_eftlink AND version=18.0.1
vendor=oracle AND product=retail_eftlink AND version=19.0.1
vendor=oracle AND product=retail_insights_cloud_service_suite AND version=19.0
vendor=oracle AND product=retail_order_broker_cloud_service AND version=19.2
vendor=oracle AND product=retail_predictive_application_server AND version=16.0.3.0
vendor=oracle AND product=retail_xstore_point_of_service AND version=15.0.4
vendor=oracle AND product=retail_xstore_point_of_service AND version=16.0.6
vendor=oracle AND product=retail_xstore_point_of_service AND version=17.0.4
vendor=oracle AND product=retail_xstore_point_of_service AND version=18.0.3
vendor=oracle AND product=retail_xstore_point_of_service AND version=19.0.2
vendor=oracle AND product=siebel_apps_-_marketing AND versionEndIncluding=21.9
vendor=oracle AND product=siebel_ui_framework AND versionEndIncluding=21.2
vendor=oracle AND product=spatial_and_graph AND version=12.2.0.1
vendor=oracle AND product=storagetek_acsls AND version=8.5.1
vendor=oracle AND product=storagetek_tape_analytics_sw_tool AND version=2.3.1
OR
vendor=Debian AND product=debian_linux AND version=9.0
vendor=Debian AND product=debian_linux AND version=10.0
vendor=Debian AND product=debian_linux AND version=11.0
OR
vendor=qos AND product=reload4j AND versionEndExcluding=1.2.18.3
 

Reference

 


Keywords

NVD

 

CVE-2020-9488

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.