Attacker Value
Unknown
0
CVE-2020-9488
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2020-9488
(Last updated November 08, 2023) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
3.7 Low
Impact Score:
1.4
Exploitability Score:
2.2
Attack Vector (AV):
Network
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
Low
Integrity (I):
None
Availability (A):
None
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
Apache Log4j 2.12.3
Apache Log4j 2.13.0
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
- apache,
- debian,
- oracle,
- qos
Products
- communications application session controller 3.9m0p1,
- communications billing and revenue management 12.0.0.3.0,
- communications billing and revenue management 7.5.0.23.0,
- communications eagle ftp table base retrieval 4.5,
- communications offline mediation controller 12.0.0.3.0,
- communications services gatekeeper 7.0,
- communications unified inventory management 7.3.0,
- communications unified inventory management 7.4.0,
- data integrator 12.2.1.3.0,
- data integrator 12.2.1.4.0,
- debian linux 10.0,
- debian linux 11.0,
- debian linux 9.0,
- enterprise manager for peoplesoft 13.4.1.1,
- financial services analytical applications infrastructure,
- financial services institutional performance analytics 8.0.6,
- financial services institutional performance analytics 8.1.0,
- financial services institutional performance analytics 8.7.0,
- financial services market risk measurement and management 8.0.6,
- financial services market risk measurement and management 8.0.8,
- financial services market risk measurement and management 8.1.0,
- financial services price creation and discovery 8.0.6,
- financial services price creation and discovery 8.0.7,
- financial services retail customer analytics 8.0.6,
- flexcube core banking,
- flexcube core banking 5.2.0,
- flexcube private banking 12.0.0,
- flexcube private banking 12.1.0,
- health sciences information manager 3.0.1,
- insurance insbridge rating and underwriting,
- insurance insbridge rating and underwriting 5.6.1.0,
- insurance policy administration j2ee 10.2.0.37,
- insurance policy administration j2ee 10.2.4.12,
- insurance policy administration j2ee 11.0.2.25,
- insurance policy administration j2ee 11.1.0.15,
- insurance policy administration j2ee 11.2.0.26,
- insurance rules palette 10.2.0.37,
- insurance rules palette 10.2.4.12,
- insurance rules palette 11.0.2.25,
- insurance rules palette 11.1.0.15,
- insurance rules palette 11.2.0.26,
- jd edwards world security a9.4,
- log4j,
- oracle goldengate application adapters 19.1.0.0.0,
- peoplesoft enterprise peopletools 8.56,
- peoplesoft enterprise peopletools 8.57,
- peoplesoft enterprise peopletools 8.58,
- policy automation,
- policy automation connector for siebel 10.4.6,
- policy automation for mobile devices,
- primavera unifier 18.8,
- primavera unifier 19.12,
- reload4j,
- retail advanced inventory planning 14.1,
- retail assortment planning 15.0.3.0,
- retail assortment planning 16.0.3.0,
- retail bulk data integration 15.0.3.0,
- retail bulk data integration 16.0.3.0,
- retail customer management and segmentation foundation 16.0,
- retail customer management and segmentation foundation 17.0,
- retail customer management and segmentation foundation 18.0,
- retail customer management and segmentation foundation 19.0,
- retail eftlink 15.0.2,
- retail eftlink 16.0.3,
- retail eftlink 17.0.2,
- retail eftlink 18.0.1,
- retail eftlink 19.0.1,
- retail insights cloud service suite 19.0,
- retail integration bus 14.1,
- retail integration bus 15.0,
- retail integration bus 16.0,
- retail order broker cloud service 16.0,
- retail order broker cloud service 18.0,
- retail order broker cloud service 19.0,
- retail order broker cloud service 19.1,
- retail order broker cloud service 19.2,
- retail order broker cloud service 19.3,
- retail predictive application server 14.1.3.0,
- retail predictive application server 15.0.3.0,
- retail predictive application server 16.0.3.0,
- retail xstore point of service 15.0.4,
- retail xstore point of service 16.0.6,
- retail xstore point of service 17.0.4,
- retail xstore point of service 18.0.3,
- retail xstore point of service 19.0.2,
- siebel apps - marketing,
- siebel ui framework,
- spatial and graph 12.2.0.1,
- spatial and graph 18c,
- spatial and graph 19c,
- storagetek acsls 8.5.1,
- storagetek tape analytics sw tool 2.3.1,
- utilities framework,
- utilities framework 2.2.0.0.0,
- utilities framework 4.2.0.2.0,
- utilities framework 4.2.0.3.0,
- utilities framework 4.4.0.0.0,
- utilities framework 4.4.0.2.0,
- weblogic server 10.3.6.0.0
References
Advisory
Miscellaneous
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: