4.3
CVE-2020-9488
- EPSS 0.01%
- Published 27.04.2020 16:15:12
- Last modified 21.11.2024 05:40:45
- Source security@apache.org
- Teams watchlist Login
- Open Login
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Data is provided by the National Vulnerability Database (NVD)
Oracle ≫ Communications Application Session Controller Version3.9m0p1
Oracle ≫ Communications Billing And Revenue Management Version7.5.0.23.0
Oracle ≫ Communications Billing And Revenue Management Version12.0.0.3.0
Oracle ≫ Communications Eagle Ftp Table Base Retrieval Version4.5
Oracle ≫ Communications Offline Mediation Controller Version12.0.0.3.0
Oracle ≫ Communications Services Gatekeeper Version7.0
Oracle ≫ Communications Unified Inventory Management Version7.3.0
Oracle ≫ Communications Unified Inventory Management Version7.4.0
Oracle ≫ Data Integrator Version12.2.1.3.0
Oracle ≫ Data Integrator Version12.2.1.4.0
Oracle ≫ Enterprise Manager For Peoplesoft Version13.4.1.1
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.6.0.0 <= 8.1.0.0.0
Oracle ≫ Financial Services Institutional Performance Analytics Version8.0.6
Oracle ≫ Financial Services Institutional Performance Analytics Version8.1.0
Oracle ≫ Financial Services Institutional Performance Analytics Version8.7.0
Oracle ≫ Financial Services Market Risk Measurement And Management Version8.0.6
Oracle ≫ Financial Services Market Risk Measurement And Management Version8.0.8
Oracle ≫ Financial Services Market Risk Measurement And Management Version8.1.0
Oracle ≫ Financial Services Price Creation And Discovery Version8.0.6
Oracle ≫ Financial Services Price Creation And Discovery Version8.0.7
Oracle ≫ Financial Services Retail Customer Analytics Version8.0.6
Oracle ≫ Flexcube Core Banking Version >= 11.5.0 <= 11.7.0
Oracle ≫ Flexcube Core Banking Version5.2.0
Oracle ≫ Flexcube Private Banking Version12.0.0
Oracle ≫ Flexcube Private Banking Version12.1.0
Oracle ≫ Health Sciences Information Manager Version3.0.1
Oracle ≫ Insurance Insbridge Rating And Underwriting Version >= 5.0.0.0 <= 5.6.0.0
Oracle ≫ Insurance Insbridge Rating And Underwriting Version5.6.1.0
Oracle ≫ Insurance Policy Administration J2ee Version10.2.0.37
Oracle ≫ Insurance Policy Administration J2ee Version10.2.4.12
Oracle ≫ Insurance Policy Administration J2ee Version11.0.2.25
Oracle ≫ Insurance Policy Administration J2ee Version11.1.0.15
Oracle ≫ Insurance Policy Administration J2ee Version11.2.0.26
Oracle ≫ Insurance Rules Palette Version10.2.0.37
Oracle ≫ Insurance Rules Palette Version10.2.4.12
Oracle ≫ Insurance Rules Palette Version11.0.2.25
Oracle ≫ Insurance Rules Palette Version11.1.0.15
Oracle ≫ Insurance Rules Palette Version11.2.0.26
Oracle ≫ Jd Edwards World Security Versiona9.4
Oracle ≫ Oracle Goldengate Application Adapters Version19.1.0.0.0
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.56
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.57
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.58
Oracle ≫ Policy Automation Version >= 12.2.0 <= 12.2.20
Oracle ≫ Policy Automation Connector For Siebel Version10.4.6
Oracle ≫ Policy Automation For Mobile Devices Version >= 12.2.0 <= 12.2.20
Oracle ≫ Primavera Unifier Version18.8
Oracle ≫ Primavera Unifier Version19.12
Oracle ≫ Retail Advanced Inventory Planning Version14.1
Oracle ≫ Retail Assortment Planning Version15.0.3.0
Oracle ≫ Retail Assortment Planning Version16.0.3.0
Oracle ≫ Retail Bulk Data Integration Version15.0.3.0
Oracle ≫ Retail Bulk Data Integration Version16.0.3.0
Oracle ≫ Retail Customer Management And Segmentation Foundation Version16.0
Oracle ≫ Retail Customer Management And Segmentation Foundation Version17.0
Oracle ≫ Retail Customer Management And Segmentation Foundation Version18.0
Oracle ≫ Retail Customer Management And Segmentation Foundation Version19.0
Oracle ≫ Retail Eftlink Version15.0.2
Oracle ≫ Retail Eftlink Version16.0.3
Oracle ≫ Retail Eftlink Version17.0.2
Oracle ≫ Retail Eftlink Version18.0.1
Oracle ≫ Retail Eftlink Version19.0.1
Oracle ≫ Retail Insights Cloud Service Suite Version19.0
Oracle ≫ Retail Integration Bus Version14.1
Oracle ≫ Retail Integration Bus Version15.0
Oracle ≫ Retail Integration Bus Version16.0
Oracle ≫ Retail Order Broker Cloud Service Version16.0
Oracle ≫ Retail Order Broker Cloud Service Version18.0
Oracle ≫ Retail Order Broker Cloud Service Version19.0
Oracle ≫ Retail Order Broker Cloud Service Version19.1
Oracle ≫ Retail Order Broker Cloud Service Version19.2
Oracle ≫ Retail Order Broker Cloud Service Version19.3
Oracle ≫ Retail Predictive Application Server Version14.1.3.0
Oracle ≫ Retail Predictive Application Server Version15.0.3.0
Oracle ≫ Retail Predictive Application Server Version16.0.3.0
Oracle ≫ Retail Xstore Point Of Service Version15.0.4
Oracle ≫ Retail Xstore Point Of Service Version16.0.6
Oracle ≫ Retail Xstore Point Of Service Version17.0.4
Oracle ≫ Retail Xstore Point Of Service Version18.0.3
Oracle ≫ Retail Xstore Point Of Service Version19.0.2
Oracle ≫ Siebel Apps - Marketing Version <= 21.9
Oracle ≫ Siebel Ui Framework Version <= 21.2
Oracle ≫ Spatial And Graph Version12.2.0.1
Oracle ≫ Spatial And Graph Version18c
Oracle ≫ Spatial And Graph Version19c
Oracle ≫ Storagetek Acsls Version8.5.1
Oracle ≫ Storagetek Tape Analytics Sw Tool Version2.3.1
Oracle ≫ Utilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
Oracle ≫ Utilities Framework Version2.2.0.0.0
Oracle ≫ Utilities Framework Version4.2.0.2.0
Oracle ≫ Utilities Framework Version4.2.0.3.0
Oracle ≫ Utilities Framework Version4.4.0.0.0
Oracle ≫ Utilities Framework Version4.4.0.2.0
Oracle ≫ Weblogic Server Version10.3.6.0.0
Debian ≫ Debian Linux Version9.0
Debian ≫ Debian Linux Version10.0
Debian ≫ Debian Linux Version11.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.01% | 0.017 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.