#VU27487 Improper Certificate Validation


Published: 2020-05-04

Vulnerability identifier: #VU27487

Vulnerability risk: Low

CVSSv3.1:

CVE-ID: CVE-2020-9488

CWE-ID: CWE-295

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Apache Log4j
Universal components / Libraries / Libraries used by multiple products

Vendor: Apache Foundation

Description

The vulnerability allows a remote attacker to perform man-in-the-middle attack.

The vulnerability exists due to the Apache Log4j SMTP appender does not validate SSL certificates. A remote attacker can perform a MitM attack, intercept and decrypt network traffic.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Apache Log4j: 2.13.1


CPE

External links
http://issues.apache.org/jira/browse/LOG4J2-2819


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability