Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2020-03624

Опубликовано: 13 апр. 2020
Источник: fstec
CVSS3: 3.7
CVSS2: 4.3
EPSS Низкий

Описание

Уязвимость реализации класса SmtpAppender библиотеки журналирования Java-программ Log4j связана с неправильным подтверждением подлинности сертификата. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, реализовать атаку типа «человек посередине»

Вендор

Red Hat Inc.
Oracle Corp.
Apache Software Foundation
Cisco Systems Inc.
АО «Концерн ВНИИНС»

Наименование ПО

Red Hat Enterprise Linux
WebLogic Server
Enterprise Repository
Fusion Middleware MapViewer
Primavera Unifier
PeopleSoft Enterprise PeopleTools
Oracle Retail Customer Management and Segmentation Foundation
Oracle Retail Order Broker
Instantis EnterpriseTrack
Agile Engineering Data Management
Oracle Data Integrator
Jboss Fuse
Utilities Framework
Application Testing Suite
OpenShift Application Runtimes
Oracle Policy Automation Connector for Siebel
JBoss Data Grid
Red Hat Single Sign-On
Red Hat Process Automation Manager
Oracle Communications Unified Inventory Management
Red Hat Descision Manager
Oracle Retail Assortment Planning
JBoss A-MQ Streaming
Oracle Communications Interactive Session Recorder
Oracle Endeca Information Discovery Studio
Oracle Retail Predictive Application Server
Retail Integration Bus
Primavera Gateway
Oracle Retail Financial Integration
Financial Services Price Creation and Discovery
Oracle Retail Service Backbone
Rapid Planning
Enterprise Manager Ops Center
Communications MetaSolv Solution
Oracle Communications Order and Service Management
Financial Services Analytical Applications Infrastructure
Oracle FLEXCUBE Investor Servicing
Oracle FLEXCUBE Private Banking
Oracle Banking Enterprise Collections
Category Management Planning & Optimization
Oracle Retail Bulk Data Integration
Oracle Retail Data Extractor for Merchandising
Oracle Retail Item Planning
Oracle Retail Macro Space Optimization
Oracle Retail Merchandise Financial Planning
Oracle Retail Regular Price Optimization
Oracle Retail Replenishment Optimization
Oracle Retail Size Profile Optimization
Retail Store Inventory Management
Communications Instant Messaging Server
Communications Network Charging and Control
Communications Billing and Revenue Management
Siebel Engineering - Installer & Deployment
Log4j
A-MQ Clients
JD Edwards EnterpriseOne Tools
Oracle Communications Network Integrity
Oracle Financial Services Lending and Leasing
Banking Platform
Oracle Insurance Data Gateway
Oracle Retail Extract Transform and Load
Data Grid
Oracle Communications Services Gatekeeper
Financial Services Retail Customer Analytics
Insurance Policy Administration J2EE
Insurance Insbridge Rating and Underwriting
Hyperion Infrastructure Technology
FLEXCUBE Core Banking
Oracle GoldenGate Application Adapters
Communications Application Session Controller
Oracle Policy Automation
Oracle Policy Automation for Mobile Devices
Oracle Insurance Rules Palette
Retail Advanced Inventory Planning
Siebel UI Framework
Oracle Health Sciences Information Manager
StorageTek Tape Analytics SW Tool
ОС ОН «Стрелец»

Версия ПО

7 (Red Hat Enterprise Linux)
10.3.6.0.0 (WebLogic Server)
12.1.3.0.0 (WebLogic Server)
11.1.1.7.0 (Enterprise Repository)
12.2.1.3.0 (Fusion Middleware MapViewer)
16.2 (Primavera Unifier)
16.1 (Primavera Unifier)
8.56 (PeopleSoft Enterprise PeopleTools)
8.57 (PeopleSoft Enterprise PeopleTools)
12.2.1.3.0 (WebLogic Server)
16.0 (Oracle Retail Customer Management and Segmentation Foundation)
17.0 (Oracle Retail Customer Management and Segmentation Foundation)
18.0 (Oracle Retail Customer Management and Segmentation Foundation)
15.0 (Oracle Retail Order Broker)
16.0 (Oracle Retail Order Broker)
17.1 (Instantis EnterpriseTrack)
17.2 (Instantis EnterpriseTrack)
17.3 (Instantis EnterpriseTrack)
6.2.1 (Agile Engineering Data Management)
8 (Red Hat Enterprise Linux)
12.2.1.3.0 (Oracle Data Integrator)
7 (Jboss Fuse)
4.4.0.0.0 (Utilities Framework)
4.2.0.3.0 (Utilities Framework)
4.2.0.2.0 (Utilities Framework)
13.3.0.1 (Application Testing Suite)
18.8 (Primavera Unifier)
1.0 (OpenShift Application Runtimes)
10.4.6 (Oracle Policy Automation Connector for Siebel)
7 (JBoss Data Grid)
7 (Red Hat Single Sign-On)
7 (Red Hat Process Automation Manager)
12.2.1.4.0 (WebLogic Server)
7.3 (Oracle Communications Unified Inventory Management)
7.4 (Oracle Communications Unified Inventory Management)
7 (Red Hat Descision Manager)
16.0.3 (Oracle Retail Assortment Planning)
- (JBoss A-MQ Streaming)
19.12 (Primavera Unifier)
от 17.7 до 17.12 включительно (Primavera Unifier)
6.1 (Oracle Communications Interactive Session Recorder)
6.2 (Oracle Communications Interactive Session Recorder)
6.3 (Oracle Communications Interactive Session Recorder)
3.2.0 (Oracle Endeca Information Discovery Studio)
15.0.3 (Oracle Retail Predictive Application Server)
16.0.3 (Oracle Retail Predictive Application Server)
18.0 (Oracle Retail Order Broker)
15.0 (Retail Integration Bus)
16.0 (Retail Integration Bus)
8.58 (PeopleSoft Enterprise PeopleTools)
15.0.3 (Oracle Retail Assortment Planning)
от 16.2.0 до 16.2.11 включительно (Primavera Gateway)
15.0 (Oracle Retail Financial Integration)
16.0 (Oracle Retail Financial Integration)
8.0.7 (Financial Services Price Creation and Discovery)
14.1.0 (Retail Integration Bus)
14.0.3 (Oracle Retail Predictive Application Server)
14.1.3 (Oracle Retail Predictive Application Server)
15.0 (Oracle Retail Service Backbone)
16.0 (Oracle Retail Service Backbone)
12.1 (Rapid Planning)
12.2 (Rapid Planning)
14.1.1.0.0 (WebLogic Server)
12.4.0.0 (Enterprise Manager Ops Center)
6.3.0 (Communications MetaSolv Solution)
7.3 (Oracle Communications Order and Service Management)
7.4 (Oracle Communications Order and Service Management)
от 8.0.6 до 8.1.0 включительно (Financial Services Analytical Applications Infrastructure)
12.1.0 (Oracle FLEXCUBE Investor Servicing)
12.3.0 (Oracle FLEXCUBE Investor Servicing)
12.4.0 (Oracle FLEXCUBE Investor Servicing)
14.0.0 (Oracle FLEXCUBE Investor Servicing)
14.1.0 (Oracle FLEXCUBE Investor Servicing)
12.0.0 (Oracle FLEXCUBE Private Banking)
12.1.0 (Oracle FLEXCUBE Private Banking)
от 2.7.0 до 2.9.0 включительно (Oracle Banking Enterprise Collections)
15.0.3 (Category Management Planning & Optimization)
15.0 (Oracle Retail Bulk Data Integration)
16.0 (Oracle Retail Bulk Data Integration)
1.9 (Oracle Retail Data Extractor for Merchandising)
1.10 (Oracle Retail Data Extractor for Merchandising)
15.0.3 (Oracle Retail Item Planning)
15.0.3 (Oracle Retail Macro Space Optimization)
15.0.3 (Oracle Retail Merchandise Financial Planning)
15.0.3 (Oracle Retail Regular Price Optimization)
16.0.3 (Oracle Retail Regular Price Optimization)
15.0.3 (Oracle Retail Replenishment Optimization)
15.0.3 (Oracle Retail Size Profile Optimization)
14.0.4 (Retail Store Inventory Management)
14.1.3 (Retail Store Inventory Management)
15.0.3 (Retail Store Inventory Management)
16.0.3 (Retail Store Inventory Management)
10.0.1.4.0 (Communications Instant Messaging Server)
от 17.12.0 до 17.12.7 включительно (Primavera Gateway)
от 18.8.0 до 18.8.9 включительно (Primavera Gateway)
от 19.12.0 до 19.12.4 включительно (Primavera Gateway)
6.0.1 (Communications Network Charging and Control)
от 12.0.0 до 12.0.3 включительно (Communications Network Charging and Control)
7.5.0.23.0 (Communications Billing and Revenue Management)
12.0.0.3.0 (Communications Billing and Revenue Management)
до 2.20.5 включительно (Siebel Engineering - Installer & Deployment)
до 2.13.2 (Log4j)
6.4 (Oracle Communications Interactive Session Recorder)
2 (A-MQ Clients)
до 9.2.3.3 (JD Edwards EnterpriseOne Tools)
от 7.3.2 до 7.3.6включительно (Oracle Communications Network Integrity)
12.5.0 (Oracle Financial Services Lending and Leasing)
от 14.1.0 до 14.8.0 включительно (Oracle Financial Services Lending and Leasing)
12.2.1.4.0 (Fusion Middleware MapViewer)
2.4.0-2.10.0 (Banking Platform)
1.0 (Oracle Insurance Data Gateway)
18.0 (Oracle Retail Data Extractor for Merchandising)
19.0 (Oracle Retail Extract Transform and Load)
14.1 (Oracle Retail Service Backbone)
8 (Data Grid)
7.0 (Oracle Communications Services Gatekeeper)
2.2.0.0.0 (Utilities Framework)
от 4.3.0.1.0 до 4.3.0.6.0 включительно (Utilities Framework)
8.0.6 (Financial Services Price Creation and Discovery)
8.0.6 (Financial Services Retail Customer Analytics)
11.0.2.25 (Insurance Policy Administration J2EE)
11.1.0.15 (Insurance Policy Administration J2EE)
от 5.0.0.0 до 5.6.0.0 включительно (Insurance Insbridge Rating and Underwriting)
5.6.1.0 (Insurance Insbridge Rating and Underwriting)
11.1.2.4 (Hyperion Infrastructure Technology)
5.2.0 (FLEXCUBE Core Banking)
от 11.5.0 до 11.7.0 включительно (FLEXCUBE Core Banking)
19.1.0.0.0 (Oracle GoldenGate Application Adapters)
3.9m0p1 (Communications Application Session Controller)
4.4.0.2.0 (Utilities Framework)
от 12.2.0 до 12.2.20 включительно (Oracle Policy Automation)
от 12.2.0 до 12.2.20 включительно (Oracle Policy Automation for Mobile Devices)
19.0 (Oracle Retail Customer Management and Segmentation Foundation)
10.2.0.37 (Insurance Policy Administration J2EE)
10.2.4.12 (Insurance Policy Administration J2EE)
11.2.0.26 (Insurance Policy Administration J2EE)
10.2.0.37 (Oracle Insurance Rules Palette)
10.2.4.12 (Oracle Insurance Rules Palette)
11.0.2.25 (Oracle Insurance Rules Palette)
11.1.0.15 (Oracle Insurance Rules Palette)
11.2.0.26 (Oracle Insurance Rules Palette)
14.1 (Retail Advanced Inventory Planning)
15.0.3.0 (Oracle Retail Bulk Data Integration)
16.0.3.0 (Oracle Retail Bulk Data Integration)
от 19.0 до 19.3 включительно (Oracle Retail Order Broker)
до 20.12 включительно (Siebel UI Framework)
12.2.1.4.0 (Oracle Data Integrator)
3.0.1 (Oracle Health Sciences Information Manager)
2.3.1 (StorageTek Tape Analytics SW Tool)
до 16.01.2023 (ОС ОН «Стрелец»)

Тип ПО

Операционная система
Сетевое программное средство
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 7
Red Hat Inc. Red Hat Enterprise Linux 8
АО «Концерн ВНИИНС» ОС ОН «Стрелец» до 16.01.2023

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4,3)
Низкий уровень опасности (базовая оценка CVSS 3.0 составляет 3,7)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для Log4j:
https://issues.apache.org/jira/browse/LOG4J2-2819
Для программных продуктов Oracle Corp.:
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpujan2021.html
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2020-9488
Для ОС ОН «Стрелец»:
Обновление программного обеспечения apache-log4j2 до версии 2.12.4-0+deb9u1

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Ссылки на источники

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 2%
0.00016
Низкий

3.7 Low

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS3: 3.7
redhat
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS3: 3.7
nvd
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVSS3: 3.7
debian
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j ...

CVSS3: 3.7
github
около 5 лет назад

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

EPSS

Процентиль: 2%
0.00016
Низкий

3.7 Low

CVSS3

4.3 Medium

CVSS2