CVE-2020-9488

Description

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Risk Information

Base Score
3.7
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.021

Associated Vulnerability

VulnerabilityOS Platform
Log4j Vulnerability (CVE-2020-9488)Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 10.3.6.0.0Windows
Vulnerabilities CVE-2020-9488 are fixed in Apache-log4j 2.13.2Windows
Vulnerabilities CVE-2020-9488 are fixed in Apache-log4j 2.12.3Windows
Vulnerabilities CVE-2020-9488 are fixed in Apache-log4j 2.3.2Windows
Vulnerabilities CVE-2021-44832,CVE-2020-9488 are fixed in Apache - Log4j Core 2.3.2Windows
Vulnerabilities CVE-2021-45105,CVE-2020-9488 are fixed in Apache - Log4j Core 2.12.3Windows
Vulnerabilities CVE-2020-9488 are fixed in Apache - Log4j Core 2.13.2Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.56Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.57Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.58Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.56Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.57Windows
Multiple Vulnerabilities are affected in Oracle Corporation PeopleSoft Enterprise PeopleTools 8.58Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.3Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.4Windows
Vulnerabilities CVE-2020-9488 are fixed in Apache-log4j for Linux 2.13.2Linux
Vulnerabilities CVE-2020-9488 are fixed in Apache-log4j for Linux 2.12.3Linux
Vulnerabilities CVE-2020-9488 are fixed in Apache-log4j for Linux 2.3.2Linux
Vulnerabilities CVE-2021-44832,CVE-2020-9488 are fixed in Apache - Log4j Core for Linux 2.3.2Linux
Vulnerabilities CVE-2021-45105,CVE-2020-9488 are fixed in Apache - Log4j Core for Linux 2.12.3Linux
Vulnerabilities CVE-2020-9488 are fixed in Apache - Log4j Core for Linux 2.13.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234