Lucene search

K
nvd[email protected]NVD:CVE-2020-9488
HistoryApr 27, 2020 - 4:15 p.m.

CVE-2020-9488

2020-04-2716:15:12
CWE-295
web.nvd.nist.gov

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.8%

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Affected configurations

NVD
Node
apachelog4jRange2.0โ€“2.3.2
OR
apachelog4jRange2.4โ€“2.12.3
OR
apachelog4jRange2.13.0โ€“2.13.2
Node
oraclecommunications_application_session_controllerMatch3.9m0p1
OR
oraclecommunications_billing_and_revenue_managementMatch7.5.0.23.0
OR
oraclecommunications_billing_and_revenue_managementMatch12.0.0.3.0
OR
oraclecommunications_eagle_ftp_table_base_retrievalMatch4.5
OR
oraclecommunications_offline_mediation_controllerMatch12.0.0.3.0
OR
oraclecommunications_services_gatekeeperMatch7.0
OR
oraclecommunications_unified_inventory_managementMatch7.3.0
OR
oraclecommunications_unified_inventory_managementMatch7.4.0
OR
oracledata_integratorMatch12.2.1.3.0
OR
oracledata_integratorMatch12.2.1.4.0
OR
oracleenterprise_manager_for_peoplesoftMatch13.4.1.1
OR
oraclefinancial_services_analytical_applications_infrastructureRange8.0.6.0.0โ€“8.1.0.0.0
OR
oraclefinancial_services_institutional_performance_analyticsMatch8.0.6
OR
oraclefinancial_services_institutional_performance_analyticsMatch8.1.0
OR
oraclefinancial_services_institutional_performance_analyticsMatch8.7.0
OR
oraclefinancial_services_market_risk_measurement_and_managementMatch8.0.6
OR
oraclefinancial_services_market_risk_measurement_and_managementMatch8.0.8
OR
oraclefinancial_services_market_risk_measurement_and_managementMatch8.1.0
OR
oraclefinancial_services_price_creation_and_discoveryMatch8.0.6
OR
oraclefinancial_services_price_creation_and_discoveryMatch8.0.7
OR
oraclefinancial_services_retail_customer_analyticsMatch8.0.6
OR
oracleflexcube_core_bankingRange11.5.0โ€“11.7.0
OR
oracleflexcube_core_bankingMatch5.2.0
OR
oracleflexcube_private_bankingMatch12.0.0
OR
oracleflexcube_private_bankingMatch12.1.0
OR
oraclehealth_sciences_information_managerMatch3.0.1
OR
oracleinsurance_insbridge_rating_and_underwritingRange5.0.0.0โ€“5.6.0.0
OR
oracleinsurance_insbridge_rating_and_underwritingMatch5.6.1.0
OR
oracleinsurance_policy_administration_j2eeMatch10.2.0.37
OR
oracleinsurance_policy_administration_j2eeMatch10.2.4.12
OR
oracleinsurance_policy_administration_j2eeMatch11.0.2.25
OR
oracleinsurance_policy_administration_j2eeMatch11.1.0.15
OR
oracleinsurance_policy_administration_j2eeMatch11.2.0.26
OR
oracleinsurance_rules_paletteMatch10.2.0.37
OR
oracleinsurance_rules_paletteMatch10.2.4.12
OR
oracleinsurance_rules_paletteMatch11.0.2.25
OR
oracleinsurance_rules_paletteMatch11.1.0.15
OR
oracleinsurance_rules_paletteMatch11.2.0.26
OR
oraclejd_edwards_world_securityMatcha9.4
OR
oracleoracle_goldengate_application_adaptersMatch19.1.0.0.0
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.56
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.57
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.58
OR
oraclepolicy_automationRange12.2.0โ€“12.2.20
OR
oraclepolicy_automation_connector_for_siebelMatch10.4.6
OR
oraclepolicy_automation_for_mobile_devicesRange12.2.0โ€“12.2.20
OR
oracleprimavera_unifierMatch18.8
OR
oracleprimavera_unifierMatch19.12
OR
oracleretail_advanced_inventory_planningMatch14.1
OR
oracleretail_assortment_planningMatch15.0.3.0
OR
oracleretail_assortment_planningMatch16.0.3.0
OR
oracleretail_bulk_data_integrationMatch15.0.3.0
OR
oracleretail_bulk_data_integrationMatch16.0.3.0
OR
oracleretail_customer_management_and_segmentation_foundationMatch16.0
OR
oracleretail_customer_management_and_segmentation_foundationMatch17.0
OR
oracleretail_customer_management_and_segmentation_foundationMatch18.0
OR
oracleretail_customer_management_and_segmentation_foundationMatch19.0
OR
oracleretail_eftlinkMatch15.0.2
OR
oracleretail_eftlinkMatch16.0.3
OR
oracleretail_eftlinkMatch17.0.2
OR
oracleretail_eftlinkMatch18.0.1
OR
oracleretail_eftlinkMatch19.0.1
OR
oracleretail_insights_cloud_service_suiteMatch19.0
OR
oracleretail_integration_busMatch14.1
OR
oracleretail_integration_busMatch15.0
OR
oracleretail_integration_busMatch16.0
OR
oracleretail_order_broker_cloud_serviceMatch16.0
OR
oracleretail_order_broker_cloud_serviceMatch18.0
OR
oracleretail_order_broker_cloud_serviceMatch19.0
OR
oracleretail_order_broker_cloud_serviceMatch19.1
OR
oracleretail_order_broker_cloud_serviceMatch19.2
OR
oracleretail_order_broker_cloud_serviceMatch19.3
OR
oracleretail_predictive_application_serverMatch14.1.3.0
OR
oracleretail_predictive_application_serverMatch15.0.3.0
OR
oracleretail_predictive_application_serverMatch16.0.3.0
OR
oracleretail_xstore_point_of_serviceMatch15.0.4
OR
oracleretail_xstore_point_of_serviceMatch16.0.6
OR
oracleretail_xstore_point_of_serviceMatch17.0.4
OR
oracleretail_xstore_point_of_serviceMatch18.0.3
OR
oracleretail_xstore_point_of_serviceMatch19.0.2
OR
oraclesiebel_apps_-_marketingRangeโ‰ค21.9
OR
oraclesiebel_ui_frameworkRangeโ‰ค21.2
OR
oraclespatial_and_graphMatch12.2.0.1
OR
oraclespatial_and_graphMatch18c
OR
oraclespatial_and_graphMatch19c
OR
oraclestoragetek_acslsMatch8.5.1
OR
oraclestoragetek_tape_analytics_sw_toolMatch2.3.1
OR
oracleutilities_frameworkRange4.3.0.1.0โ€“4.3.0.6.0
OR
oracleutilities_frameworkMatch2.2.0.0.0
OR
oracleutilities_frameworkMatch4.2.0.2.0
OR
oracleutilities_frameworkMatch4.2.0.3.0
OR
oracleutilities_frameworkMatch4.4.0.0.0
OR
oracleutilities_frameworkMatch4.4.0.2.0
OR
oracleweblogic_serverMatch10.3.6.0.0
Node
debiandebian_linuxMatch9.0
OR
debiandebian_linuxMatch10.0
OR
debiandebian_linuxMatch11.0
Node
qosreload4jRange<1.2.18.3

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

3.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.8%