LOW · 3.7

CVE-2020-9488

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messa...

Vulnerability Description

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS Score

3.7

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ApacheLog4J>= 2.0, < 2.3.2
OracleCommunications Application Session Controller3.9m0p1
OracleCommunications Billing And Revenue Management7.5.0.23.0
OracleCommunications Eagle Ftp Table Base Retrieval4.5
OracleCommunications Offline Mediation Controller12.0.0.3.0
OracleCommunications Services Gatekeeper7.0
OracleCommunications Unified Inventory Management7.3.0
OracleData Integrator12.2.1.3.0
OracleEnterprise Manager For Peoplesoft13.4.1.1
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6.0.0, <= 8.1.0.0.0
OracleFinancial Services Institutional Performance Analytics8.0.6
OracleFinancial Services Market Risk Measurement And Management8.0.6
OracleFinancial Services Price Creation And Discovery8.0.6
OracleFinancial Services Retail Customer Analytics8.0.6
OracleFlexcube Core Banking>= 11.5.0, <= 11.7.0
OracleFlexcube Private Banking12.0.0
OracleHealth Sciences Information Manager3.0.1
OracleInsurance Insbridge Rating And Underwriting>= 5.0.0.0, <= 5.6.0.0
OracleInsurance Policy Administration J2Ee10.2.0.37
OracleInsurance Rules Palette10.2.0.37

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-9488?

CVE-2020-9488 is a vulnerability with a CVSS score of 3.7 (LOW). Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messa...

How severe is CVE-2020-9488?

CVE-2020-9488 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-9488?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Log4J, Oracle Communications Application Session Controller, Oracle Communications Billing And Revenue Management, Oracle Communications Eagle Ftp Table Base Retrieval, Oracle Communications Offline Mediation Controller.