GHSA-vwqq-5vrc-xw9h · Severity: low · Ecosystem: maven — Improper validation of certificate with host mismatch in Apache Log4j SMTP appender
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Conclusion & alert: CVE-2020-9488 is rated Low Risk (14.3/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.02%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 2.19% | 0.02% | -2.17% |
| 2 | 2025-11-18 | 0.02% | 2.19% | +2.17% |
| 3 | 2025-03-30 | — | 0.02% | — |
Full EPSS history (18 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 3.7 | 3.1 | LOW |
|
2.2 | 1.4 | [email protected] |
| 3.7 | 3.1 | LOW |
|
2.2 | 1.4 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-vwqq-5vrc-xw9h · Severity: low · Ecosystem: maven — Improper validation of certificate with host mismatch in Apache Log4j SMTP appender
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2020-9488 not yet assigned priority: Debian including 1 source packages (apache-log4j2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-9488 |
gentoo
|
normal | CVE-2020-9488: 1 GLSA(s) (202402-16), 1 atom(s) (dev-java/log4j); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2020-9488 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2020-9488 |
suse
|
low | CVE-2020-9488 severity low: SUSE including 24 source package names (log4j, log4j-2.13.2-1.9, …), 83 product×package rows across 44 product lines (SUSE Enterprise Storage 7, SUSE Linux Enterprise High Performance Computing 12 SP4, … (44 product lines)): Known Not Affected 63, Fixed 20. | https://www.suse.com/security/cve/CVE-2020-9488/ |
ubuntu
|
medium | CVE-2020-9488 medium priority: Ubuntu including 1 source packages (apache-log4j2), 17 status rows across 17 suites (bionic, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 10, ignored 3, released 2, DNE 1, needs-triage 1. | https://ubuntu.com/security/CVE-2020-9488 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | log4j | >= 2.0, < 2.3.2 | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* |
| apache | log4j | >= 2.4, < 2.12.3 | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* |
| apache | log4j | >= 2.13.0, < 2.13.2 | cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:* |
| oracle | communications_application_session_controller | 3.9m0p1 | cpe:2.3:a:oracle:communications_application_session_controller:3.9m0p1:*:*:*:*:*:*:* |
| oracle | communications_billing_and_revenue_management | 7.5.0.23.0 | cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:* |
| oracle | communications_billing_and_revenue_management | 12.0.0.3.0 | cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:* |
| oracle | communications_eagle_ftp_table_base_retrieval | 4.5 | cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5:*:*:*:*:*:*:* |
| oracle | communications_offline_mediation_controller | 12.0.0.3.0 | cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3.0:*:*:*:*:*:*:* |
| oracle | communications_services_gatekeeper | 7.0 | cpe:2.3:a:oracle:communications_services_gatekeeper:7.0:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.3.0 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.0:*:*:*:*:*:*:* |
| oracle | communications_unified_inventory_management | 7.4.0 | cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.0:*:*:*:*:*:*:* |
| oracle | data_integrator | 12.2.1.3.0 | cpe:2.3:a:oracle:data_integrator:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | data_integrator | 12.2.1.4.0 | cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | enterprise_manager_for_peoplesoft | 13.4.1.1 | cpe:2.3:a:oracle:enterprise_manager_for_peoplesoft:13.4.1.1:*:*:*:*:*:*:* |
| oracle | financial_services_analytical_applications_infrastructure | >= 8.0.6.0.0, <= 8.1.0.0.0 | cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* |
| oracle | financial_services_institutional_performance_analytics | 8.0.6 | cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.0.6:*:*:*:*:*:*:* |
| oracle | financial_services_institutional_performance_analytics | 8.1.0 | cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.1.0:*:*:*:*:*:*:* |
| oracle | financial_services_institutional_performance_analytics | 8.7.0 | cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.7.0:*:*:*:*:*:*:* |
| oracle | financial_services_market_risk_measurement_and_management | 8.0.6 | cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:* |
| oracle | financial_services_market_risk_measurement_and_management | 8.0.8 | cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:* |
| oracle | financial_services_market_risk_measurement_and_management | 8.1.0 | cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.1.0:*:*:*:*:*:*:* |
| oracle | financial_services_price_creation_and_discovery | 8.0.6 | cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.6:*:*:*:*:*:*:* |
| oracle | financial_services_price_creation_and_discovery | 8.0.7 | cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.7:*:*:*:*:*:*:* |
| oracle | financial_services_retail_customer_analytics | 8.0.6 | cpe:2.3:a:oracle:financial_services_retail_customer_analytics:8.0.6:*:*:*:*:*:*:* |
| oracle | flexcube_core_banking | >= 11.5.0, <= 11.7.0 | cpe:2.3:a:oracle:flexcube_core_banking:*:*:*:*:*:*:*:* |
| oracle | flexcube_core_banking | 5.2.0 | cpe:2.3:a:oracle:flexcube_core_banking:5.2.0:*:*:*:*:*:*:* |
| oracle | flexcube_private_banking | 12.0.0 | cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:* |
| oracle | flexcube_private_banking | 12.1.0 | cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:* |
| oracle | health_sciences_information_manager | 3.0.1 | cpe:2.3:a:oracle:health_sciences_information_manager:3.0.1:*:*:*:*:*:*:* |
| oracle | insurance_insbridge_rating_and_underwriting | >= 5.0.0.0, <= 5.6.0.0 | cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:*:*:*:*:*:*:*:* |
| oracle | insurance_insbridge_rating_and_underwriting | 5.6.1.0 | cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.6.1.0:*:*:*:*:*:*:* |
| oracle | insurance_policy_administration_j2ee | 10.2.0.37 | cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.0.37:*:*:*:*:*:*:* |
| oracle | insurance_policy_administration_j2ee | 10.2.4.12 | cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.4.12:*:*:*:*:*:*:* |
| oracle | insurance_policy_administration_j2ee | 11.0.2.25 | cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.0.2.25:*:*:*:*:*:*:* |
| oracle | insurance_policy_administration_j2ee | 11.1.0.15 | cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.1.0.15:*:*:*:*:*:*:* |
| oracle | insurance_policy_administration_j2ee | 11.2.0.26 | cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.2.0.26:*:*:*:*:*:*:* |
| oracle | insurance_rules_palette | 10.2.0.37 | cpe:2.3:a:oracle:insurance_rules_palette:10.2.0.37:*:*:*:*:*:*:* |
| oracle | insurance_rules_palette | 10.2.4.12 | cpe:2.3:a:oracle:insurance_rules_palette:10.2.4.12:*:*:*:*:*:*:* |
| oracle | insurance_rules_palette | 11.0.2.25 | cpe:2.3:a:oracle:insurance_rules_palette:11.0.2.25:*:*:*:*:*:*:* |
| oracle | insurance_rules_palette | 11.1.0.15 | cpe:2.3:a:oracle:insurance_rules_palette:11.1.0.15:*:*:*:*:*:*:* |
| oracle | insurance_rules_palette | 11.2.0.26 | cpe:2.3:a:oracle:insurance_rules_palette:11.2.0.26:*:*:*:*:*:*:* |
| oracle | jd_edwards_world_security | a9.4 | cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:* |
| oracle | oracle_goldengate_application_adapters | 19.1.0.0.0 | cpe:2.3:a:oracle:oracle_goldengate_application_adapters:19.1.0.0.0:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.56 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.57 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.58 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* |
| oracle | policy_automation | >= 12.2.0, <= 12.2.20 | cpe:2.3:a:oracle:policy_automation:*:*:*:*:*:*:*:* |
| oracle | policy_automation_connector_for_siebel | 10.4.6 | cpe:2.3:a:oracle:policy_automation_connector_for_siebel:10.4.6:*:*:*:*:*:*:* |
| oracle | policy_automation_for_mobile_devices | >= 12.2.0, <= 12.2.20 | cpe:2.3:a:oracle:policy_automation_for_mobile_devices:*:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 18.8 | cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 19.12 | cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:* |
| oracle | retail_advanced_inventory_planning | 14.1 | cpe:2.3:a:oracle:retail_advanced_inventory_planning:14.1:*:*:*:*:*:*:* |
| oracle | retail_assortment_planning | 15.0.3.0 | cpe:2.3:a:oracle:retail_assortment_planning:15.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_assortment_planning | 16.0.3.0 | cpe:2.3:a:oracle:retail_assortment_planning:16.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_bulk_data_integration | 15.0.3.0 | cpe:2.3:a:oracle:retail_bulk_data_integration:15.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_bulk_data_integration | 16.0.3.0 | cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_customer_management_and_segmentation_foundation | 16.0 | cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:16.0:*:*:*:*:*:*:* |
| oracle | retail_customer_management_and_segmentation_foundation | 17.0 | cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:17.0:*:*:*:*:*:*:* |
| oracle | retail_customer_management_and_segmentation_foundation | 18.0 | cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:* |
| oracle | retail_customer_management_and_segmentation_foundation | 19.0 | cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:* |
| oracle | retail_eftlink | 15.0.2 | cpe:2.3:a:oracle:retail_eftlink:15.0.2:*:*:*:*:*:*:* |
| oracle | retail_eftlink | 16.0.3 | cpe:2.3:a:oracle:retail_eftlink:16.0.3:*:*:*:*:*:*:* |
| oracle | retail_eftlink | 17.0.2 | cpe:2.3:a:oracle:retail_eftlink:17.0.2:*:*:*:*:*:*:* |
| oracle | retail_eftlink | 18.0.1 | cpe:2.3:a:oracle:retail_eftlink:18.0.1:*:*:*:*:*:*:* |
| oracle | retail_eftlink | 19.0.1 | cpe:2.3:a:oracle:retail_eftlink:19.0.1:*:*:*:*:*:*:* |
| oracle | retail_insights_cloud_service_suite | 19.0 | cpe:2.3:a:oracle:retail_insights_cloud_service_suite:19.0:*:*:*:*:*:*:* |
| oracle | retail_integration_bus | 14.1 | cpe:2.3:a:oracle:retail_integration_bus:14.1:*:*:*:*:*:*:* |
| oracle | retail_integration_bus | 15.0 | cpe:2.3:a:oracle:retail_integration_bus:15.0:*:*:*:*:*:*:* |
| oracle | retail_integration_bus | 16.0 | cpe:2.3:a:oracle:retail_integration_bus:16.0:*:*:*:*:*:*:* |
| oracle | retail_order_broker_cloud_service | 16.0 | cpe:2.3:a:oracle:retail_order_broker_cloud_service:16.0:*:*:*:*:*:*:* |
| oracle | retail_order_broker_cloud_service | 18.0 | cpe:2.3:a:oracle:retail_order_broker_cloud_service:18.0:*:*:*:*:*:*:* |
| oracle | retail_order_broker_cloud_service | 19.0 | cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.0:*:*:*:*:*:*:* |
| oracle | retail_order_broker_cloud_service | 19.1 | cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.1:*:*:*:*:*:*:* |
| oracle | retail_order_broker_cloud_service | 19.2 | cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.2:*:*:*:*:*:*:* |
| oracle | retail_order_broker_cloud_service | 19.3 | cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.3:*:*:*:*:*:*:* |
| oracle | retail_predictive_application_server | 14.1.3.0 | cpe:2.3:a:oracle:retail_predictive_application_server:14.1.3.0:*:*:*:*:*:*:* |
| oracle | retail_predictive_application_server | 15.0.3.0 | cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_predictive_application_server | 16.0.3.0 | cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3.0:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 15.0.4 | cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0.4:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 16.0.6 | cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:* |