← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-9488

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

No Active Exploit Signals
CVSS Base Score
3.7
LOW
Exploitability:2.3
Impact Score:1.5
EPSS Probability:7.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-295 ↗CWE-295 Improper Certificate Validation

Affected Products & Versions

Vendor Product Affected Versions
Apache Apache Log4j log4j-core 2.13.0 (affected), log4j-core < 2.12.3 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
7.814%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2020-03-01T00:00:00
Published2020-04-27T15:36:10
Last Updated2026-05-29T16:07:52

LINK COPIED TO CLIPBOARD