Lucene search

K
ibmIBM3FE63A3F5C5015BF12CBC5431C7DB0BF49847105404A82C433D9F62224F6903F
HistoryJul 30, 2021 - 5:03 a.m.

Security Bulletin: Apache Log4j Vulnerability Affects IBM Control Center (CVE-2020-9488)

2021-07-3005:03:13
www.ibm.com
72

0.002 Low

EPSS

Percentile

56.7%

Summary

Apache Log4j is vulnerable to a man-in-the-middle attack

Vulnerability Details

CVEID:CVE-2020-9488
**DESCRIPTION:**Apache Log4j is vulnerable to a man-in-the-middle attack, caused by improper certificate validation with host mismatch in the SMTP appender. An attacker could exploit this vulnerability to launch a man-in-the-middle attack and gain access to the communication channel between endpoints to obtain sensitive information or further compromise the system.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/180824 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Control Center 6.2.0.0

Remediation/Fixes

Product

|

VRMF

|

iFix

|

Remediation

โ€”|โ€”|โ€”|โ€”

IBM Control Center

|

6.2.0.0

|

iFix09

|

Fix Central - 6.2.0.0

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm control centereq6.2.0.0

0.002 Low

EPSS

Percentile

56.7%