Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
07 Nov 2023, 03:26
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-04-27 16:15
Updated : 2024-02-28 17:47
NVD link : CVE-2020-9488
Mitre link : CVE-2020-9488
CVE.ORG link : CVE-2020-9488
JSON object : View
Products Affected
oracle
- financial_services_analytical_applications_infrastructure
- retail_customer_management_and_segmentation_foundation
- communications_services_gatekeeper
- flexcube_private_banking
- communications_unified_inventory_management
- enterprise_manager_for_peoplesoft
- jd_edwards_world_security
- peoplesoft_enterprise_peopletools
- retail_order_broker_cloud_service
- policy_automation_connector_for_siebel
- primavera_unifier
- communications_billing_and_revenue_management
- utilities_framework
- financial_services_retail_customer_analytics
- communications_offline_mediation_controller
- communications_application_session_controller
- oracle_goldengate_application_adapters
- communications_eagle_ftp_table_base_retrieval
- retail_bulk_data_integration
- retail_eftlink
- siebel_apps_-_marketing
- spatial_and_graph
- policy_automation_for_mobile_devices
- weblogic_server
- insurance_insbridge_rating_and_underwriting
- siebel_ui_framework
- financial_services_price_creation_and_discovery
- storagetek_tape_analytics_sw_tool
- flexcube_core_banking
- financial_services_market_risk_measurement_and_management
- insurance_policy_administration_j2ee
- data_integrator
- insurance_rules_palette
- retail_assortment_planning
- health_sciences_information_manager
- retail_integration_bus
- retail_predictive_application_server
- policy_automation
- retail_insights_cloud_service_suite
- retail_advanced_inventory_planning
- retail_xstore_point_of_service
- financial_services_institutional_performance_analytics
- storagetek_acsls
apache
- log4j
qos
- reload4j
debian
- debian_linux
CWE
CWE-295
Improper Certificate Validation