Improper Certificate Validation in Apache Log4j - CVE-2020-9488

 

Improper Certificate Validation in Apache Log4j - CVE-2020-9488

Published: May 4, 2020


Vulnerability identifier: #VU27487
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9488
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform man-in-the-middle attack.

The vulnerability exists due to the Apache Log4j SMTP appender does not validate SSL certificates. A remote attacker can perform a MitM attack, intercept and decrypt network traffic.


Affected software

Apache Log4j
Gentoo Linux
JD Edwards World Security
Oracle Insurance Data Gateway
Oracle Communications Interactive Session Recorder
Oracle Communications Services Gatekeeper
Oracle Communications Billing and Revenue Management
Oracle Communications Instant Messaging Server
Oracle Communications Offline Mediation Controller
apache-log4j2 (Debian package)
Oracle Utilities Framework
Oracle Banking Platform
Oracle Communications Network Charging and Control
Oracle Financial Services Analytical Applications Infrastructure
Oracle Insurance Rules Palette
Oracle Policy Automation Connector for Siebel
Oracle FLEXCUBE Private Banking
Oracle FLEXCUBE Investor Servicing
Oracle Policy Automation
Oracle Data Integrator
Oracle Retail Xstore Point of Service
Oracle Retail Order Broker
ObjectScale
IBM Cloud Pak for Watson AIOps
DevOps
IBM Sterling Order Management
IBM Cloud Pak for Multicloud Management
Enterprise Manager for Peoplesoft
Primavera Unifier
Oracle GoldenGate Application Adapters
IBM Disconnected Log Collector
JD Edwards EnterpriseOne Tools
StorageTek Tape Analytics SW Tool
Oracle Communications Application Session Controller
Oracle Communications Unified Inventory Management
Oracle Financial Services Price Creation and Discovery
Oracle Financial Services Institutional Performance Analytics
Oracle StorageTek ACSLS
Log Analysis
Netcool Operations Insight
IBM Cloud Application Performance Management (APM)
IBM Security Access Manager for Enterprise Single-Sign On
Oracle Health Sciences Information Manager
IBM Content Navigator
Oracle Insurance Insbridge Rating and Underwriting
Oracle FLEXCUBE Core Banking
IBM Qradar SIEM
Oracle Financial Services Market Risk Measurement and Management
Dell Data Lakehouse
JBoss Data Grid
JBoss Data Virtualization
Oracle Financial Services Retail Customer Analytics
Instantis EnterpriseTrack
PeopleSoft Enterprise PeopleTools
Oracle Insurance Policy Administration
Oracle Fusion Middleware MapViewer
Oracle Retail Bulk Data Integration
Oracle WebLogic Server
Oracle Retail Predictive Application Server
Primavera Gateway
Fuse
Oracle Policy Automation for Mobile Devices
Oracle Retail Advanced Inventory Planning
Oracle Retail EFTLink
Oracle Retail Assortment Planning
Oracle Retail Customer Management and Segmentation Foundation
Oracle Retail Insights Cloud Service Suite
Oracle Retail Integration Bus
Siebel UI Framework

How to mitigate CVE-2020-9488

Install updates from vendor's website.

Apache Log4j - update to 2.13.2
apache-log4j2 (Debian package) - addressed in versions 2.15.0-1~deb10u1, 2.15.0-1~deb11u1
IBM Cloud Pak for Multicloud Management - update to 2.3.8
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008 LA2, 3.2.0 IF004
Oracle Insurance Insbridge Rating and Underwriting - update to 5.6.1.0
JBoss Data Virtualization - addressed in versions 6.4.8.SP1, 6.4.8 SP2
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF01
Log Analysis - update to 1.3.7.2
Dell Data Lakehouse - update to 1.4.0.0
ObjectScale - update to 1.4.0
IBM Disconnected Log Collector - update to 1.6
Netcool Operations Insight - update to 1.6.7
IBM Cloud Pak for Watson AIOps - update to 3.7.1
DevOps - update to 7.0.0.2
Fuse - update to 7.10.0
JBoss Data Grid - update to 8.1.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Security Access Manager for Enterprise Single-Sign On - update to 8.2.2 Fix Pack 15
JD Edwards EnterpriseOne Tools - update to 9.2.3.3
IBM Sterling Order Management - update to 10.0.2403.1

External References

Related Security Bulletins