ZeroHour

CVE-2020-9488

CVSS 3.1
3.7 low
EPSS
8%p94
Published
()
Modified
Description

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Vendors
apacheoracledebianqos
Products
log4j, communications application session controller, communications billing and revenue management, communications eagle ftp table base retrieval, communications offline mediation controller, communications services gatekeeper, communications unified inventory management, data integrator, enterprise manager for peoplesoft, financial services analytical applications infrastructure, financial services institutional performance analytics, financial services market risk measurement and management
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.