CVE-2020-9488

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
VendorProductVersion
apachelog4j
2.0 ≤
𝑥
< 2.3.2
apachelog4j
2.4 ≤
𝑥
< 2.12.3
apachelog4j
2.13.0 ≤
𝑥
< 2.13.2
oraclecommunications_application_session_controller
3.9m0p1:m0p1
oraclecommunications_billing_and_revenue_management
7.5.0.23.0
oraclecommunications_billing_and_revenue_management
12.0.0.3.0
oraclecommunications_eagle_ftp_table_base_retrieval
4.5
oraclecommunications_offline_mediation_controller
12.0.0.3.0
oraclecommunications_services_gatekeeper
7.0
oraclecommunications_unified_inventory_management
7.3.0
oraclecommunications_unified_inventory_management
7.4.0
oracledata_integrator
12.2.1.3.0
oracledata_integrator
12.2.1.4.0
oracleenterprise_manager_for_peoplesoft
13.4.1.1
oraclefinancial_services_analytical_applications_infrastructure
8.0.6.0.0 ≤
𝑥
≤ 8.1.0.0.0
oraclefinancial_services_institutional_performance_analytics
8.0.6
oraclefinancial_services_institutional_performance_analytics
8.1.0
oraclefinancial_services_institutional_performance_analytics
8.7.0
oraclefinancial_services_market_risk_measurement_and_management
8.0.6
oraclefinancial_services_market_risk_measurement_and_management
8.0.8
oraclefinancial_services_market_risk_measurement_and_management
8.1.0
oraclefinancial_services_price_creation_and_discovery
8.0.6
oraclefinancial_services_price_creation_and_discovery
8.0.7
oraclefinancial_services_retail_customer_analytics
8.0.6
oracleflexcube_core_banking
11.5.0 ≤
𝑥
≤ 11.7.0
oracleflexcube_core_banking
5.2.0
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
oraclehealth_sciences_information_manager
3.0.1
oracleinsurance_insbridge_rating_and_underwriting
5.0.0.0 ≤
𝑥
≤ 5.6.0.0
oracleinsurance_insbridge_rating_and_underwriting
5.6.1.0
oracleinsurance_policy_administration_j2ee
10.2.0.37
oracleinsurance_policy_administration_j2ee
10.2.4.12
oracleinsurance_policy_administration_j2ee
11.0.2.25
oracleinsurance_policy_administration_j2ee
11.1.0.15
oracleinsurance_policy_administration_j2ee
11.2.0.26
oracleinsurance_rules_palette
10.2.0.37
oracleinsurance_rules_palette
10.2.4.12
oracleinsurance_rules_palette
11.0.2.25
oracleinsurance_rules_palette
11.1.0.15
oracleinsurance_rules_palette
11.2.0.26
oracleoracle_goldengate_application_adapters
19.1.0.0.0
oraclepeoplesoft_enterprise_peopletools
8.56
oraclepeoplesoft_enterprise_peopletools
8.57
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepolicy_automation
12.2.0 ≤
𝑥
≤ 12.2.20
oraclepolicy_automation_connector_for_siebel
10.4.6
oraclepolicy_automation_for_mobile_devices
12.2.0 ≤
𝑥
≤ 12.2.20
oracleprimavera_unifier
18.8
oracleprimavera_unifier
19.12
oracleretail_advanced_inventory_planning
14.1
oracleretail_assortment_planning
15.0.3.0
oracleretail_assortment_planning
16.0.3.0
oracleretail_bulk_data_integration
15.0.3.0
oracleretail_bulk_data_integration
16.0.3.0
oracleretail_customer_management_and_segmentation_foundation
16.0
oracleretail_customer_management_and_segmentation_foundation
17.0
oracleretail_customer_management_and_segmentation_foundation
18.0
oracleretail_customer_management_and_segmentation_foundation
19.0
oracleretail_eftlink
15.0.2
oracleretail_eftlink
16.0.3
oracleretail_eftlink
17.0.2
oracleretail_eftlink
18.0.1
oracleretail_eftlink
19.0.1
oracleretail_insights_cloud_service_suite
19.0
oracleretail_integration_bus
14.1
oracleretail_integration_bus
15.0
oracleretail_integration_bus
16.0
oracleretail_order_broker_cloud_service
16.0
oracleretail_order_broker_cloud_service
18.0
oracleretail_order_broker_cloud_service
19.0
oracleretail_order_broker_cloud_service
19.1
oracleretail_order_broker_cloud_service
19.2
oracleretail_order_broker_cloud_service
19.3
oracleretail_predictive_application_server
14.1.3.0
oracleretail_predictive_application_server
15.0.3.0
oracleretail_predictive_application_server
16.0.3.0
oracleretail_xstore_point_of_service
15.0.4
oracleretail_xstore_point_of_service
16.0.6
oracleretail_xstore_point_of_service
17.0.4
oracleretail_xstore_point_of_service
18.0.3
oracleretail_xstore_point_of_service
19.0.2
oraclesiebel_apps_-_marketing
𝑥
≤ 21.9
oraclesiebel_ui_framework
𝑥
≤ 21.2
oraclespatial_and_graph
12.2.0.1
oraclestoragetek_acsls
8.5.1
oraclestoragetek_tape_analytics_sw_tool
2.3.1
oracleutilities_framework
4.3.0.1.0 ≤
𝑥
≤ 4.3.0.6.0
oracleutilities_framework
2.2.0.0.0
oracleutilities_framework
4.2.0.2.0
oracleutilities_framework
4.2.0.3.0
oracleutilities_framework
4.4.0.0.0
oracleutilities_framework
4.4.0.2.0
oracleweblogic_server
10.3.6.0.0
debiandebian_linux
9.0
debiandebian_linux
10.0
debiandebian_linux
11.0
qosreload4j
𝑥
< 1.2.18.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache-log4j2
bullseye
2.17.1-1~deb11u1
fixed
jessie
no-dsa
bullseye (security)
2.17.0-1~deb11u1
fixed
sid
2.19.0-2
fixed
trixie
2.19.0-2
fixed
bookworm
2.19.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache-log4j2
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
ignored
focal
Fixed 2.16.0-0.20.04.1
released
eoan
ignored
bionic
needs-triage
xenial
ignored
trusty
dne
References