Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2020-04-27 09:15
Updated : 2022-05-12 08:00
NVD link : CVE-2020-9488
Mitre link : CVE-2020-9488
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
oracle
- insurance_policy_administration_j2ee
- siebel_ui_framework
- oracle_goldengate_application_adapters
- retail_integration_bus
- primavera_unifier
- retail_eftlink
- communications_offline_mediation_controller
- policy_automation_for_mobile_devices
- peoplesoft_enterprise_peopletools
- health_sciences_information_manager
- communications_application_session_controller
- retail_order_broker_cloud_service
- storagetek_tape_analytics_sw_tool
- communications_unified_inventory_management
- retail_predictive_application_server
- financial_services_analytical_applications_infrastructure
- weblogic_server
- financial_services_price_creation_and_discovery
- jd_edwards_world_security
- policy_automation
- spatial_and_graph
- policy_automation_connector_for_siebel
- insurance_insbridge_rating_and_underwriting
- enterprise_manager_for_peoplesoft
- financial_services_retail_customer_analytics
- flexcube_core_banking
- flexcube_private_banking
- utilities_framework
- financial_services_institutional_performance_analytics
- retail_xstore_point_of_service
- retail_bulk_data_integration
- retail_insights_cloud_service_suite
- storagetek_acsls
- retail_customer_management_and_segmentation_foundation
- retail_advanced_inventory_planning
- siebel_apps_-_marketing
- financial_services_market_risk_measurement_and_management
- communications_services_gatekeeper
- data_integrator
- insurance_rules_palette
- communications_billing_and_revenue_management
- communications_eagle_ftp_table_base_retrieval
- retail_assortment_planning
qos
- reload4j
debian
- debian_linux
apache
- log4j