CVE-2020-9488
—CVSS 3.1
3.7 low
EPSS
8%p94
Published
()
Modified
Description
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
- Vendors
- apacheoracledebianqos
- Products
- log4j, communications application session controller, communications billing and revenue management, communications eagle ftp table base retrieval, communications offline mediation controller, communications services gatekeeper, communications unified inventory management, data integrator, enterprise manager for peoplesoft, financial services analytical applications infrastructure, financial services institutional performance analytics, financial services market risk measurement and management
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.