CVE-2020-9488: Low severity IBM QRadar SIEM vulnerability
Apache Log4j is vulnerable to a man-in-the-middle attack, caused by improper certificate validation with host mismatch in the SMTP appender. An attacker could exploit this vulnerability to launch a man-in-the-middle attack and gain access to the communication channel between endpoints to obtain sensitive information or further compromise the system.
Other sources
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender prior to version 2.13.2. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender.
— GitHub
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender.
Reference: https://issues.apache.org/jira/browse/LOG4J2-2819
— Red Hat
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache-log4j2to a version that resolves this vulnerability.Fixed in 2.17.1-1~deb10u1Fixed in 2.17.0-1~deb10u1Fixed in 2.17.1-1~deb11u1Fixed in 2.17.0-1~deb11u1Fixed in 2.19.0-2 - Upgrade
Upgrade
redhat/qpid-cppto a version that resolves this vulnerability.Fixed in 0:1.36.0-31.el6_10a - Upgrade
Upgrade
redhat/qpid-protonto a version that resolves this vulnerability.Fixed in 0:0.32.0-1.el6_10 - Upgrade
Upgrade
redhat/qpid-cppto a version that resolves this vulnerability.Fixed in 0:1.36.0-31.el7a - Upgrade
Upgrade
redhat/qpid-protonto a version that resolves this vulnerability.Fixed in 0:0.32.0-2.el7 - Upgrade
Upgrade
redhat/nodejs-rheato a version that resolves this vulnerability.Fixed in 0:1.0.24-1.el8 - Upgrade
Upgrade
redhat/qpid-protonto a version that resolves this vulnerability.Fixed in 0:0.32.0-2.el8 - Upgrade
Upgrade
maven/org.apache.logging.log4j:log4j-coreto a version that resolves this vulnerability.Fixed in 2.3.2 - Upgrade
Upgrade
maven/org.apache.logging.log4j:log4j-coreto a version that resolves this vulnerability.Fixed in 2.12.3 - Upgrade
Upgrade
maven/org.apache.logging.log4j:log4jto a version that resolves this vulnerability.Fixed in 2.3.2 - Upgrade
Upgrade
maven/org.apache.logging.log4j:log4jto a version that resolves this vulnerability.Fixed in 2.12.3 - Upgrade
Upgrade
maven/org.apache.logging.log4j:log4j-coreto a version that resolves this vulnerability.Fixed in 2.13.2 - Upgrade
Upgrade
maven/org.apache.logging.log4j:log4jto a version that resolves this vulnerability.Fixed in 2.13.2 - Upgrade
Upgrade
redhat/log4jto a version that resolves this vulnerability.Fixed in 2.13.2 - Upgrade
Upgrade
Apache Log4jto a version that resolves this vulnerability.Fixed in 2.12.3 - Upgrade
Upgrade
Apache Log4jto a version that resolves this vulnerability.Fixed in 2.13.1 - Configuration
For Log4j versions prior to 2.13.2, set the system property mail.smtp.ssl.checkserveridentity=true to globally enable hostname verification for SMTPS connections.
Apache Log4j SMTP appender (mail.smtp.ssl.checkserveridentity system property) mail.smtp.ssl.checkserveridentity = true
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-9488.
What is the severity of CVE-2020-9488?
The severity of CVE-2020-9488 is high, with a severity value of 3.7.
Which software is affected by CVE-2020-9488?
The Apache Log4j SMTP appender versions 2.12.3 and 2.13.1 are affected by CVE-2020-9488.
How can CVE-2020-9488 be exploited?
CVE-2020-9488 can be exploited through a man-in-the-middle attack intercepting SMTPS connections and leaking log messages sent through the appender.
How do I fix CVE-2020-9488?
To fix CVE-2020-9488, upgrade to Apache Log4j version 2.13.2.