Vulnerability Intelligence Report
CVE-2020-9488
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
No Active Exploit Signals
CVSS Base Score
3.7
LOW
Exploitability:2.3
Impact Score:1.5
EPSS Probability:7.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-295 ↗CWE-295 Improper Certificate Validation
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Apache | Apache Log4j | log4j-core 2.13.0 (affected), log4j-core < 2.12.3 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
7.814%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Apache Software Foundation · Vendor · USA |
| Reserved | 2020-03-01T00:00:00 |
| Published | 2020-04-27T15:36:10 |
| Last Updated | 2026-05-29T16:07:52 |
Community Chatter & Buzz