SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-9488

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender.

LOW 3.7EPSS 8.10%

Does this matter?

Lower severity and a low EPSS score (8.10%). Track it; it rarely justifies an emergency change on its own.

Description

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS 3.1
3.7 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
8.10% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
apache/log4j · oracle/communications application session controller · oracle/communications billing and revenue management · oracle/communications eagle ftp table base retrieval · oracle/communications offline mediation controller · oracle/communications services gatekeeper · oracle/communications unified inventory management · oracle/data integrator · oracle/enterprise manager for peoplesoft · oracle/financial services analytical applications infrastructure · oracle/financial services institutional performance analytics · oracle/financial services market risk measurement and management · oracle/financial services price creation and discovery · oracle/financial services retail customer analytics · oracle/flexcube core banking · oracle/flexcube private banking · oracle/health sciences information manager · oracle/insurance insbridge rating and underwriting · oracle/insurance policy administration j2ee · oracle/insurance rules palette · +26 more
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.