Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Log4j
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Oracle
Subscribe
|
Communications Application Session Controller
Subscribe
Communications Billing And Revenue Management
Subscribe
Communications Eagle Ftp Table Base Retrieval
Subscribe
Communications Offline Mediation Controller
Subscribe
Communications Services Gatekeeper
Subscribe
Communications Unified Inventory Management
Subscribe
Data Integrator
Subscribe
Enterprise Manager For Peoplesoft
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Financial Services Institutional Performance Analytics
Subscribe
Financial Services Market Risk Measurement And Management
Subscribe
Financial Services Price Creation And Discovery
Subscribe
Financial Services Retail Customer Analytics
Subscribe
Flexcube Core Banking
Subscribe
Flexcube Private Banking
Subscribe
Health Sciences Information Manager
Subscribe
Insurance Insbridge Rating And Underwriting
Subscribe
Insurance Policy Administration J2ee
Subscribe
Insurance Rules Palette
Subscribe
Jd Edwards World Security
Subscribe
Oracle Goldengate Application Adapters
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Policy Automation
Subscribe
Policy Automation Connector For Siebel
Subscribe
Policy Automation For Mobile Devices
Subscribe
Primavera Unifier
Subscribe
Retail Advanced Inventory Planning
Subscribe
Retail Assortment Planning
Subscribe
Retail Bulk Data Integration
Subscribe
Retail Customer Management And Segmentation Foundation
Subscribe
Retail Eftlink
Subscribe
Retail Insights Cloud Service Suite
Subscribe
Retail Integration Bus
Subscribe
Retail Order Broker Cloud Service
Subscribe
Retail Predictive Application Server
Subscribe
Retail Xstore Point Of Service
Subscribe
Siebel Apps - Marketing
Subscribe
Siebel Ui Framework
Subscribe
Spatial And Graph
Subscribe
Storagetek Acsls
Subscribe
Storagetek Tape Analytics Sw Tool
Subscribe
Utilities Framework
Subscribe
Weblogic Server
Subscribe
|
|
Qos
Subscribe
|
Reload4j
Subscribe
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2852-1 | apache-log4j2 security update |
Debian DSA |
DSA-5020-1 | apache-log4j2 security update |
EUVD |
EUVD-2020-0518 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1 |
Github GHSA |
GHSA-vwqq-5vrc-xw9h | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T10:26:16.370Z
Reserved: 2020-03-01T00:00:00
Link: CVE-2020-9488
No data.
Status : Modified
Published: 2020-04-27T16:15:12.897
Modified: 2024-11-21T05:40:45.037
Link: CVE-2020-9488
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA