Improper validation of certificate with host mismatch in Apache Log4j - CVE-2025-68161

 

Improper validation of certificate with host mismatch in Apache Log4j - CVE-2025-68161

Published: December 22, 2025


Vulnerability identifier: #VU120231
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2025-68161
CWE-ID: CWE-297
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to the Socket Appender does not perform TLS hostname verification of the peer certificate, even when the "verifyHostName" configuration attribute or the "log4j2.sslVerifyHostName"  system property is set to true. A remote attacker can perform MitM attack and intercept or redirect the log traffic. 


Affected software

Apache Log4j
APM Internet Service Monitoring Agent
B2B Advanced Communications
Db2 Developer Extension
PowerVM NovaLink
Guardium Data Security Center (GDSC)
Oracle Healthcare Master Person Index
OpenPages for IBM Cloud Pak for Data
DevOps
Oracle Business Intelligence Enterprise Edition
Oracle Financial Services Analytical Applications Infrastructure
Maximo Application Suite - Monitor Component
InfoSphere Data Architect
OpenPages Cloud pak for data service version
IBM Engineering Systems Design Rhapsody
Integration Bus for z/OS
webMethods BPM
ApplinX
Oracle Data Integrator
Oracle Communications Policy Management
Oracle Retail Service Backbone
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
StreamSets Data Collector
Maximo Asset Configuration Manager
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Client
Maximo Scheduler Optimizer
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
openSUSE Leap
IBM App Connect for Manufacturing
IBM Data Studio Client
Oracle Configuration Manager
Primavera Unifier
IBM Disconnected Log Collector
Oracle Communications Convergence
Communications Unified Assurance
Oracle Communications Instant Messaging Server
Oracle Communications Billing and Revenue Management
Oracle Communications Offline Mediation Controller
IBM Content Navigator
IBM SPSS Analytic Server
Oracle Product Lifecycle Analytics
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling External Authentication Server
IBM UrbanCode Release
IBM Sterling Connect:Direct Web Services
IBM Sterling Control Center
Oracle Communications Network Integrity
Oracle Communications IP Service Activator
Oracle Communications Unified Inventory Management
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition
Oracle Financial Services Behavior Detection Platform
Oracle Financial Services Enterprise Case Management
Netcool/OMNIbus
IBM Tivoli Netcool/OMNIbus WebGUI
Oracle Financial Services Model Management and Governance
Oracle Healthcare Data Repository
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
Oracle Life Sciences Empirica Signal
IBM Transformation Extender Advanced
Oracle Middleware Common Libraries and Tools
Enterprise Manager Base Platform
Oracle Enterprise Command Center Framework
IBM SPSS Modeler
IBM Business Automation Workflow
AppDynamics Java Agent
Splunk AppDynamics Database Agent
Oracle Communications EAGLE Element Management System
IBM Cloud Object Storage Systems
IBM Decision Optimization for Cloud Pak for Data
Oracle Health Sciences Information Manager
Oracle Utilities Application Framework
Oracle Utilities Testing Accelerator
Oracle Insurance Policy Administration
Oracle Managed File Transfer
Oracle Business Process Management Suite
Oracle WebCenter Sites
Oracle Retail Extract Tranform and Load
Oracle Banking Virtual Account Management
Oracle Retail Bulk Data Integration
Oracle Retail Price Management
IBM App Connect for Healthcare
IBM Qradar SIEM
IBM License Metric Tool
Oracle Communications Order and Service Management
SAP NetWeaver AS JAVA
Oracle WebLogic Server
Oracle Retail Predictive Application Server
Primavera Gateway
PeopleSoft Enterprise PeopleTools
IBM InfoSphere Information Server
Oracle Communications BRM - Elastic Charging Engine
Oracle GoldenGate Big Data and Application Adapters
Oracle GoldenGate
IBM DB2
IBM App Connect Enterprise
Siebel CRM Development
Identity Manager
Oracle Retail Fiscal Management
Oracle Retail Merchandise Financial Planning
Oracle Retail Assortment Planning
Oracle Retail Merchandising System
Oracle Retail Financial Integration
Oracle Retail EFTLink
Oracle Retail Integration Bus
Siebel CRM Integration
log4j-jcl
log4j
log4j-slf4j
log4j-javadoc

How to mitigate CVE-2025-68161

Install updates from vendor's website.

Apache Log4j - update to 2.25.3
B2B Advanced Communications - update to 1.0.0.13
Db2 Developer Extension - update to 1.1.2
PowerVM NovaLink - addressed in versions 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422
IBM App Connect for Manufacturing - addressed in versions 3.0.1.3, 13.0.0.3
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008 LA2, 3.2.0 IF004
Guardium Data Security Center (GDSC) - update to 3.8.8
IBM Security Guardium Key Lifecycle Manager (GKLM) - addressed in versions 5.0.0 FP3, 5.1.0 FP2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
OpenPages for IBM Cloud Pak for Data - update to 5.3.1
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.17, 6.4.0.6
IBM Sterling Control Center - addressed in versions 6.3.1.0.6, 6.4.1.0.1, 6.4.2.0.1
DevOps - update to 7.0.0.7
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
Netcool/OMNIbus - update to 8.1.0.37
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.41
IBM SPSS Collaboration and Deployment Services - update to 9.0.0.0.0.1
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.37, 8.7.31, 9.0.24, 9.1.15
Maximo Application Suite - Monitor Component - addressed in versions 8.10.28, 8.11.26, 9.0.18, 9.1.8
InfoSphere Data Architect - update to 9.2.1
IBM License Metric Tool - update to 9.2.44
OpenPages Cloud pak for data service version - update to 9.6.1
IBM Engineering Systems Design Rhapsody - addressed in versions 10.0.0.5, 10.0.1.0.6, 10.0.2.0.4
IBM Transformation Extender Advanced - addressed in versions 10.0.1.12, 10.0.2.1 1iFix
webMethods BPM - addressed in versions 10.15 Fix 2, 11.1 Fix 2, 12.1 Fix 1
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 2
IBM App Connect Enterprise - addressed in versions 12.0.12.26, 13.0.7.2
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
AppDynamics Java Agent - update to 26.1.0
Splunk AppDynamics Database Agent - update to 26.1.0
IBM Disconnected Log Collector - update to 2.0.1
log4j-jcl - update to 2.20.0-150200.4.30.1
log4j - update to 2.20.0-150200.4.30.1
log4j-slf4j - update to 2.20.0-150200.4.30.1
log4j-javadoc - update to 2.20.0-150200.4.30.1
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 6
watsonx Assistant Cartridge - update to 5.4
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4
StreamSets Data Collector - update to 7.2.0
Maximo Asset Configuration Manager - addressed in versions 8.1.29, 9.0.109
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
Storage Protect Client - update to 8.2.1
Maximo Scheduler Optimizer - addressed in versions 9.0.25, 9.1.14, 9.2.1
IBM DB2 - addressed in versions 11.5.9, 12.1.4

External References

Related Security Bulletins