4.3

CVE-2020-9488

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Data is provided by the National Vulnerability Database (NVD)
ApacheLog4j Version >= 2.0 < 2.3.2
ApacheLog4j Version >= 2.4 < 2.12.3
ApacheLog4j Version >= 2.13.0 < 2.13.2
OracleData Integrator Version12.2.1.3.0
OracleData Integrator Version12.2.1.4.0
OracleFlexcube Core Banking Version >= 11.5.0 <= 11.7.0
OracleFlexcube Core Banking Version5.2.0
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleInsurance Insbridge Rating And Underwriting Version >= 5.0.0.0 <= 5.6.0.0
OracleInsurance Rules Palette Version10.2.0.37
OracleInsurance Rules Palette Version10.2.4.12
OracleInsurance Rules Palette Version11.0.2.25
OracleInsurance Rules Palette Version11.1.0.15
OracleInsurance Rules Palette Version11.2.0.26
OraclePolicy Automation Version >= 12.2.0 <= 12.2.20
OraclePolicy Automation For Mobile Devices Version >= 12.2.0 <= 12.2.20
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OracleRetail Assortment Planning Version15.0.3.0
OracleRetail Assortment Planning Version16.0.3.0
OracleRetail Bulk Data Integration Version15.0.3.0
OracleRetail Bulk Data Integration Version16.0.3.0
OracleRetail Eftlink Version15.0.2
OracleRetail Eftlink Version16.0.3
OracleRetail Eftlink Version17.0.2
OracleRetail Eftlink Version18.0.1
OracleRetail Eftlink Version19.0.1
OracleRetail Integration Bus Version14.1
OracleRetail Integration Bus Version15.0
OracleRetail Integration Bus Version16.0
OracleSiebel Apps - Marketing Version <= 21.9
OracleSiebel Ui Framework Version <= 21.2
OracleSpatial And Graph Version12.2.0.1
OracleSpatial And Graph Version18c
OracleSpatial And Graph Version19c
OracleStoragetek Acsls Version8.5.1
OracleUtilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
OracleUtilities Framework Version2.2.0.0.0
OracleUtilities Framework Version4.2.0.2.0
OracleUtilities Framework Version4.2.0.3.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
OracleWeblogic Server Version10.3.6.0.0
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
DebianDebian Linux Version11.0
QosReload4j Version < 1.2.18.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.01% 0.017
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://issues.apache.org/jira/browse/LOG4J2-2819
Patch
Vendor Advisory
Issue Tracking
Mitigation