CVE-2020-9488

Aliases:GHSA-vwqq-5vrc-xw9h
Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 27 Apr 2020, 15:36
Last modified:29 May 2026, 16:07

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
0.03% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Apr 2020, 15:36
Published
Vulnerability first disclosed
29 May 2026, 16:07
Last Modified
Vulnerability information updated

Description

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS Metrics

  • v3.1LOWScore: 3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.03% Percentile: 9%

Techniques & Countermeasures

  • CWE-295Improper Certificate Validation

    The product does not validate, or incorrectly validates, a certificate.

Affected Systems

  • apacheapache log4j

    log4j-core 2.13.0 | ≥ log4j-core, < 2.12.3

  • apachelog4j

    ≥ 2.0, < 2.3.2 | ≥ 2.4, < 2.12.3 | ≥ 2.13.0, < 2.13.2

  • debiandebian_linux

    9.0 | 10.0 | 11.0

  • org.apache.logging.log4jlog4j

    ≥ 2.13.0, < 2.13.2 | ≥ 2.4.0, < 2.12.3 | < 2.3.2

  • org.apache.logging.log4jlog4j-core

    ≥ 2.13.0, < 2.13.2 | ≥ 2.4.0, < 2.12.3 | < 2.3.2

  • oraclecommunications_application_session_controller

    3.9m0p1

  • oraclecommunications_billing_and_revenue_management

    7.5.0.23.0 | 12.0.0.3.0

  • oraclecommunications_eagle_ftp_table_base_retrieval

    4.5

  • oraclecommunications_offline_mediation_controller

    12.0.0.3.0

  • oraclecommunications_services_gatekeeper

    7.0

  • oraclecommunications_unified_inventory_management

    7.3.0 | 7.4.0

  • oracledata_integrator

    12.2.1.3.0 | 12.2.1.4.0

  • oracleenterprise_manager_for_peoplesoft

    13.4.1.1

  • oraclefinancial_services_analytical_applications_infrastructure

    ≥ 8.0.6.0.0, ≤ 8.1.0.0.0

  • oraclefinancial_services_institutional_performance_analytics

    8.0.6 | 8.1.0 | 8.7.0

  • oraclefinancial_services_market_risk_measurement_and_management

    8.0.6 | 8.0.8 | 8.1.0

  • oraclefinancial_services_price_creation_and_discovery

    8.0.6 | 8.0.7

  • oraclefinancial_services_retail_customer_analytics

    8.0.6

  • oracleflexcube_core_banking

    ≥ 11.5.0, ≤ 11.7.0 | 5.2.0

  • oracleflexcube_private_banking

    12.0.0 | 12.1.0

  • oraclehealth_sciences_information_manager

    3.0.1

  • oracleinsurance_insbridge_rating_and_underwriting

    ≥ 5.0.0.0, ≤ 5.6.0.0 | 5.6.1.0

  • oracleinsurance_policy_administration_j2ee

    10.2.0.37 | 10.2.4.12 | 11.0.2.25 | 11.1.0.15 | 11.2.0.26

  • oracleinsurance_rules_palette

    10.2.0.37 | 10.2.4.12 | 11.0.2.25 | 11.1.0.15 | 11.2.0.26

  • oraclejd_edwards_world_security

    a9.4

  • oracleoracle_goldengate_application_adapters

    19.1.0.0.0

  • oraclepeoplesoft_enterprise_peopletools

    8.56 | 8.57 | 8.58

  • oraclepolicy_automation

    ≥ 12.2.0, ≤ 12.2.20

  • oraclepolicy_automation_connector_for_siebel

    10.4.6

  • oraclepolicy_automation_for_mobile_devices

    ≥ 12.2.0, ≤ 12.2.20

  • oracleprimavera_unifier

    18.8 | 19.12

  • oracleretail_advanced_inventory_planning

    14.1

  • oracleretail_assortment_planning

    15.0.3.0 | 16.0.3.0

  • oracleretail_bulk_data_integration

    15.0.3.0 | 16.0.3.0

  • oracleretail_customer_management_and_segmentation_foundation

    16.0 | 17.0 | 18.0 | 19.0

  • oracleretail_eftlink

    15.0.2 | 16.0.3 | 17.0.2 | 18.0.1 | 19.0.1

  • oracleretail_insights_cloud_service_suite

    19.0

  • oracleretail_integration_bus

    14.1 | 15.0 | 16.0

  • oracleretail_order_broker_cloud_service

    16.0 | 18.0 | 19.0 | 19.1 | 19.2 | 19.3

  • oracleretail_predictive_application_server

    14.1.3.0 | 15.0.3.0 | 16.0.3.0

  • oracleretail_xstore_point_of_service

    15.0.4 | 16.0.6 | 17.0.4 | 18.0.3 | 19.0.2

  • oraclesiebel_apps_-_marketing

    ≤ 21.9

  • oraclesiebel_ui_framework

    ≤ 21.2

  • oraclespatial_and_graph

    12.2.0.1 | 18c | 19c

  • oraclestoragetek_acsls

    8.5.1

  • oraclestoragetek_tape_analytics_sw_tool

    2.3.1

  • oracleutilities_framework

    ≥ 4.3.0.1.0, ≤ 4.3.0.6.0 | 2.2.0.0.0 | 4.2.0.2.0 | 4.2.0.3.0 | 4.4.0.0.0 | 4.4.0.2.0

  • UnknownWebLogic Server

    10.3.6.0.0

  • qosreload4j

    < 1.2.18.3

References (90)