Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2020-9488 Details
Description
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026Exploitation: NoneAutomatable: NoTechnical Impact: Partial
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
| CWE-295 | Improper Certificate Validation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apache log4j | >= 2.0, < 2.3.2 >= 2.4, < 2.12.3 >= 2.13.0, < 2.13.2 |
CPE
Remediation
| |
| oracle communications application session controller | 3.9m0p1 |
CPE
Remediation
| |
| oracle communications billing and revenue management | 7.5.0.23.0 12.0.0.3.0 |
CPE
Remediation
| |
| oracle communications eagle ftp table base retrieval | 4.5 |
CPE
Remediation
| |
| oracle communications offline mediation controller | 12.0.0.3.0 |
CPE
Remediation
| |
| oracle communications services gatekeeper | 7.0 |
CPE
Remediation
| |
| oracle communications unified inventory management | 7.3.0 7.4.0 |
CPE
Remediation
| |
| oracle data integrator | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle enterprise manager for peoplesoft | 13.4.1.1 |
CPE
Remediation
| |
| oracle financial services analytical applications infrastructure | >= 8.0.6.0.0, <= 8.1.0.0.0 |
CPE
Remediation
| |
| oracle financial services institutional performance analytics | 8.0.6 8.1.0 8.7.0 |
CPE
Remediation
| |
| oracle financial services market risk measurement and management | 8.0.6 8.0.8 8.1.0 |
CPE
Remediation
| |
| oracle financial services price creation and discovery | 8.0.6 8.0.7 |
CPE
Remediation
| |
| oracle financial services retail customer analytics | 8.0.6 |
CPE
Remediation
| |
| oracle flexcube core banking | >= 11.5.0, <= 11.7.0 5.2.0 |
CPE
Remediation
| |
| oracle flexcube private banking | 12.0.0 12.1.0 |
CPE
Remediation
| |
| oracle health sciences information manager | 3.0.1 |
CPE
Remediation
| |
| oracle insurance insbridge rating and underwriting | >= 5.0.0.0, <= 5.6.0.0 5.6.1.0 |
CPE
Remediation
| |
| oracle insurance policy administration j2ee | 10.2.0.37 10.2.4.12 11.0.2.25 11.1.0.15 11.2.0.26 |
CPE
Remediation
| |
| oracle insurance rules palette | 10.2.0.37 10.2.4.12 11.0.2.25 11.1.0.15 11.2.0.26 |
CPE
Remediation
| |
| oracle jd edwards world security | a9.4 |
CPE
Remediation
| |
| oracle oracle goldengate application adapters | 19.1.0.0.0 |
CPE
Remediation
| |
| oracle peoplesoft enterprise peopletools | 8.56 8.57 8.58 |
CPE
Remediation
| |
| oracle policy automation | >= 12.2.0, <= 12.2.20 |
CPE
Remediation
| |
| oracle policy automation connector for siebel | 10.4.6 |
CPE
Remediation
| |
| oracle policy automation for mobile devices | >= 12.2.0, <= 12.2.20 |
CPE
Remediation
| |
| oracle primavera unifier | 18.8 19.12 |
CPE
Remediation
| |
| oracle retail advanced inventory planning | 14.1 |
CPE
Remediation
| |
| oracle retail assortment planning | 15.0.3.0 16.0.3.0 |
CPE
Remediation
| |
| oracle retail bulk data integration | 15.0.3.0 16.0.3.0 |
CPE
Remediation
| |
| oracle retail customer management and segmentation foundation | 16.0 17.0 18.0 19.0 |
CPE
Remediation
| |
| oracle retail eftlink | 15.0.2 16.0.3 17.0.2 18.0.1 19.0.1 |
CPE
Remediation
| |
| oracle retail insights cloud service suite | 19.0 |
CPE
Remediation
| |
| oracle retail integration bus | 14.1 15.0 16.0 |
CPE
Remediation
| |
| oracle retail order broker cloud service | 16.0 18.0 19.0 19.1 19.2 19.3 |
CPE
Remediation
| |
| oracle retail predictive application server | 14.1.3.0 15.0.3.0 16.0.3.0 |
CPE
Remediation
| |
| oracle retail xstore point of service | 15.0.4 16.0.6 17.0.4 18.0.3 19.0.2 |
CPE
Remediation
| |
| oracle siebel apps - marketing | <= 21.9 |
CPE
Remediation
| |
| oracle siebel ui framework | <= 21.2 |
CPE
Remediation
| |
| oracle spatial and graph | 12.2.0.1 18c 19c |
CPE
Remediation
| |
| oracle storagetek acsls | 8.5.1 |
CPE
Remediation
| |
| oracle storagetek tape analytics sw tool | 2.3.1 |
CPE
Remediation
| |
| oracle utilities framework | >= 4.3.0.1.0, <= 4.3.0.6.0 2.2.0.0.0 4.2.0.2.0 4.2.0.3.0 4.4.0.0.0 4.4.0.2.0 |
CPE
Remediation
| |
| oracle weblogic server | 10.3.6.0.0 |
CPE
Remediation
| |
| debian debian linux | 9.0 10.0 11.0 |
CPE
Remediation
| |
| qos reload4j | < 1.2.18.3 |
CPE
Remediation
| |
Change History
46 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| May 12, 2022 | Modified Analysis | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Apr 8, 2022 | Modified Analysis | [email protected] |
| Mar 21, 2022 | CVE Modified | [email protected] |
| Mar 2, 2022 | Modified Analysis | [email protected] |
| Dec 27, 2021 | CVE Modified | [email protected] |
| Dec 12, 2021 | CVE Modified | [email protected] |
| Dec 2, 2021 | Modified Analysis | [email protected] |
| Oct 20, 2021 | CVE Modified | [email protected] |
| Jun 17, 2021 | CVE Modified | [email protected] |
| Jun 14, 2021 | CVE Modified | [email protected] |
| May 10, 2021 | CVE Modified | [email protected] |
| Mar 15, 2021 | Modified Analysis | [email protected] |
| Feb 25, 2021 | CVE Modified | [email protected] |
| Feb 18, 2021 | Modified Analysis | [email protected] |
| Feb 18, 2021 | CVE Modified | [email protected] |
| Feb 16, 2021 | CVE Modified | [email protected] |
| Feb 9, 2021 | CVE Modified | [email protected] |
| Jan 28, 2021 | Modified Analysis | [email protected] |
| Jan 28, 2021 | CVE Modified | [email protected] |
| Jan 27, 2021 | CVE Modified | [email protected] |
| Jan 26, 2021 | CVE Modified | [email protected] |
| Jan 20, 2021 | CVE Modified | [email protected] |
| Jan 18, 2021 | CVE Modified | [email protected] |
| Dec 23, 2020 | Modified Analysis | [email protected] |
| Dec 16, 2020 | CVE Modified | [email protected] |
| Dec 8, 2020 | CVE Modified | [email protected] |
| Dec 8, 2020 | CVE Modified | [email protected] |
| Oct 20, 2020 | CVE Modified | [email protected] |
| Jul 15, 2020 | CVE Modified | [email protected] |
| Jul 15, 2020 | CVE Modified | [email protected] |
| May 15, 2020 | CVE Modified | [email protected] |
| May 14, 2020 | CVE Modified | [email protected] |
| May 14, 2020 | CVE Modified | [email protected] |
| May 4, 2020 | CVE Modified | [email protected] |
| May 4, 2020 | CVE Modified | [email protected] |
| May 4, 2020 | CVE Modified | [email protected] |
| May 4, 2020 | CVE Modified | [email protected] |
| May 4, 2020 | CVE Modified | [email protected] |
| Apr 30, 2020 | Initial Analysis | [email protected] |