Disclosed
CVE-2020-9488
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Exploitation Probability (EPSS)
Low Priority0.03%
The Exploit Prediction Scoring System (EPSS) uses machine learning to estimate the probability that a vulnerability will be exploited in the wild within the next 30 days.
0% (Theoretical)100% (Certainty)
7-Day Exploitation Trend
Vulnerability Timeline
2 eventsApr 27, 2020
Vulnerability Disclosed
Published to component-level vulnerability database.
Nov 7, 2023
Last Updated
Record updated with new analysis or tags.
Threat Actor Attribution
PREMIUM INTELAssociated Groups:Lazarus Group, APT28
Ransomware Campaigns:LockBit 3.0, BlackCat
IoCs (Indicators):14 IPs, 3 Hashes
Remediation & Mitigation
SOLUTIONOfficial patches and mitigation steps are available for this vulnerability.
# Update Command
apt-get update && apt-get upgrade -y specific-package
# Verify installation
dpkg -l | grep package-name
apt-get update && apt-get upgrade -y specific-package
# Verify installation
dpkg -l | grep package-name
Affected Products
98 Total
apache/log4jAll Versions
oracle/communications_application_session_controller3.9m0p1
oracle/communications_billing_and_revenue_management7.5.0.23.0
oracle/communications_billing_and_revenue_management12.0.0.3.0
oracle/communications_eagle_ftp_table_base_retrieval4.5
References
https://issues.apache.org/jira/browse/LOG4J2-2819Apache
Issue TrackingMitigationPatchVendor Advisory
https://lists.apache.org/thread.html/r0a2699f724156a558afd1abb6c044fb9132caa66dce861b82699722a%40%3Cjira.kafka.apache.org%3EApache
https://lists.apache.org/thread.html/r0df3d7a5acb98c57e64ab9266aa21eeee1d9b399addb96f9cf1cbe05%40%3Cdev.zookeeper.apache.org%3EApache
https://lists.apache.org/thread.html/r1fc73f0e16ec2fa249d3ad39a5194afb9cc5afb4c023dc0bab5a5881%40%3Cissues.hive.apache.org%3EApache
Am I Vulnerable?
Check your domain or package.json for CVE-2020-9488 exposure.
Vulnerability Details
CVSS Base Score
3.7/ 10
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Published Date
Apr 27, 2020
Last Modified
Nov 7, 2023
Need Manual Validation?
Automated scanners flag false positives. Get a manual pentest validation for this CVE.