Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"vendor_product": "debian:debian_linux",
"extracted_events": [
{
"last_affected": "9.0"
},
{
"last_affected": "10.0"
},
{
"last_affected": "11.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:communications_application_session_controller:3.9m0p1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_application_session_controller",
"extracted_events": [
{
"last_affected": "3.9m0p1"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_billing_and_revenue_management",
"extracted_events": [
{
"last_affected": "7.5.0.23.0"
},
{
"last_affected": "12.0.0.3.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_eagle_ftp_table_base_retrieval",
"extracted_events": [
{
"last_affected": "4.5"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_offline_mediation_controller",
"extracted_events": [
{
"last_affected": "12.0.0.3.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:communications_services_gatekeeper:7.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_services_gatekeeper",
"extracted_events": [
{
"last_affected": "7.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_unified_inventory_management",
"extracted_events": [
{
"last_affected": "7.3.0"
},
{
"last_affected": "7.4.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:data_integrator:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:data_integrator",
"extracted_events": [
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:enterprise_manager_for_peoplesoft:13.4.1.1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:enterprise_manager_for_peoplesoft",
"extracted_events": [
{
"last_affected": "13.4.1.1"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:financial_services_analytical_applications_infrastructure",
"extracted_events": [
{
"introduced": "8.0.6.0.0"
},
{
"last_affected": "8.1.0.0.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.0.6:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.1.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.7.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:financial_services_institutional_performance_analytics",
"extracted_events": [
{
"last_affected": "8.0.6"
},
{
"last_affected": "8.1.0"
},
{
"last_affected": "8.7.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.1.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:financial_services_market_risk_measurement_and_management",
"extracted_events": [
{
"last_affected": "8.0.6"
},
{
"last_affected": "8.0.8"
},
{
"last_affected": "8.1.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.6:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.7:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:financial_services_price_creation_and_discovery",
"extracted_events": [
{
"last_affected": "8.0.6"
},
{
"last_affected": "8.0.7"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:financial_services_retail_customer_analytics:8.0.6:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:financial_services_retail_customer_analytics",
"extracted_events": [
{
"last_affected": "8.0.6"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:flexcube_core_banking:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:flexcube_core_banking:5.2.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:flexcube_core_banking",
"extracted_events": [
{
"introduced": "11.5.0"
},
{
"last_affected": "11.7.0"
},
{
"last_affected": "5.2.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:flexcube_private_banking",
"extracted_events": [
{
"last_affected": "12.0.0"
},
{
"last_affected": "12.1.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:health_sciences_information_manager:3.0.1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:health_sciences_information_manager",
"extracted_events": [
{
"last_affected": "3.0.1"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.6.1.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:insurance_insbridge_rating_and_underwriting",
"extracted_events": [
{
"introduced": "5.0.0.0"
},
{
"last_affected": "5.6.0.0"
},
{
"last_affected": "5.6.1.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.0.37:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.4.12:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.0.2.25:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.1.0.15:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.2.0.26:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:insurance_policy_administration_j2ee",
"extracted_events": [
{
"last_affected": "10.2.0.37"
},
{
"last_affected": "10.2.4.12"
},
{
"last_affected": "11.0.2.25"
},
{
"last_affected": "11.1.0.15"
},
{
"last_affected": "11.2.0.26"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:insurance_rules_palette:10.2.0.37:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_rules_palette:10.2.4.12:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_rules_palette:11.0.2.25:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_rules_palette:11.1.0.15:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:insurance_rules_palette:11.2.0.26:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:insurance_rules_palette",
"extracted_events": [
{
"last_affected": "10.2.0.37"
},
{
"last_affected": "10.2.4.12"
},
{
"last_affected": "11.0.2.25"
},
{
"last_affected": "11.1.0.15"
},
{
"last_affected": "11.2.0.26"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:jd_edwards_world_security",
"extracted_events": [
{
"last_affected": "a9.4"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:oracle_goldengate_application_adapters:19.1.0.0.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:oracle_goldengate_application_adapters",
"extracted_events": [
{
"last_affected": "19.1.0.0.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:peoplesoft_enterprise_peopletools",
"extracted_events": [
{
"last_affected": "8.56"
},
{
"last_affected": "8.57"
},
{
"last_affected": "8.58"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:policy_automation:*:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:policy_automation",
"extracted_events": [
{
"introduced": "12.2.0"
},
{
"last_affected": "12.2.20"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:policy_automation_connector_for_siebel:10.4.6:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:policy_automation_connector_for_siebel",
"extracted_events": [
{
"last_affected": "10.4.6"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:policy_automation_for_mobile_devices:*:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:policy_automation_for_mobile_devices",
"extracted_events": [
{
"introduced": "12.2.0"
},
{
"last_affected": "12.2.20"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:primavera_unifier",
"extracted_events": [
{
"last_affected": "18.8"
},
{
"last_affected": "19.12"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:retail_advanced_inventory_planning:14.1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:retail_advanced_inventory_planning",
"extracted_events": [
{
"last_affected": "14.1"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:retail_assortment_planning:15.0.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_assortment_planning:16.0.3.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:retail_assortment_planning",
"extracted_events": [
{
"last_affected": "15.0.3.0"
},
{
"last_affected": "16.0.3.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:retail_bulk_data_integration:15.0.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:retail_bulk_data_integration",
"extracted_events": [
{
"last_affected": "15.0.3.0"
},
{
"last_affected": "16.0.3.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:16.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:17.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:retail_customer_management_and_segmentation_foundation",
"extracted_events": [
{
"last_affected": "16.0"
},
{
"last_affected": "17.0"
},
{
"last_affected": "18.0"
},
{
"last_affected": "19.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:retail_eftlink:15.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_eftlink:16.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_eftlink:17.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_eftlink:18.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_eftlink:19.0.1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:retail_eftlink",
"extracted_events": [
{
"last_affected": "15.0.2"
},
{
"last_affected": "16.0.3"
},
{
"last_affected": "17.0.2"
},
{
"last_affected": "18.0.1"
},
{
"last_affected": "19.0.1"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:retail_insights_cloud_service_suite:19.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:retail_insights_cloud_service_suite",
"extracted_events": [
{
"last_affected": "19.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:retail_integration_bus:14.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_integration_bus:15.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_integration_bus:16.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:retail_integration_bus",
"extracted_events": [
{
"last_affected": "14.1"
},
{
"last_affected": "15.0"
},
{
"last_affected": "16.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:retail_order_broker_cloud_service:16.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_order_broker_cloud_service:18.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.3:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:retail_order_broker_cloud_service",
"extracted_events": [
{
"last_affected": "16.0"
},
{
"last_affected": "18.0"
},
{
"last_affected": "19.0"
},
{
"last_affected": "19.1"
},
{
"last_affected": "19.2"
},
{
"last_affected": "19.3"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:retail_predictive_application_server:14.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:retail_predictive_application_server",
"extracted_events": [
{
"last_affected": "14.1.3.0"
},
{
"last_affected": "15.0.3.0"
},
{
"last_affected": "16.0.3.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0.2:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:retail_xstore_point_of_service",
"extracted_events": [
{
"last_affected": "15.0.4"
},
{
"last_affected": "16.0.6"
},
{
"last_affected": "17.0.4"
},
{
"last_affected": "18.0.3"
},
{
"last_affected": "19.0.2"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:siebel_apps_-_marketing:*:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:siebel_apps_-_marketing",
"extracted_events": [
{
"last_affected": "21.9"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:siebel_ui_framework",
"extracted_events": [
{
"last_affected": "21.2"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:spatial_and_graph:12.2.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:spatial_and_graph:18c:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:spatial_and_graph:19c:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:spatial_and_graph",
"extracted_events": [
{
"last_affected": "12.2.0.1"
},
{
"last_affected": "18c"
},
{
"last_affected": "19c"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:storagetek_acsls:8.5.1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:storagetek_acsls",
"extracted_events": [
{
"last_affected": "8.5.1"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:storagetek_tape_analytics_sw_tool:2.3.1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:storagetek_tape_analytics_sw_tool",
"extracted_events": [
{
"last_affected": "2.3.1"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:utilities_framework:*:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:utilities_framework:2.2.0.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:utilities_framework:4.2.0.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:utilities_framework:4.2.0.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:utilities_framework:4.4.0.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:utilities_framework:4.4.0.2.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:utilities_framework",
"extracted_events": [
{
"introduced": "4.3.0.1.0"
},
{
"last_affected": "4.3.0.6.0"
},
{
"last_affected": "2.2.0.0.0"
},
{
"last_affected": "4.2.0.2.0"
},
{
"last_affected": "4.2.0.3.0"
},
{
"last_affected": "4.4.0.0.0"
},
{
"last_affected": "4.4.0.2.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:weblogic_server",
"extracted_events": [
{
"last_affected": "10.3.6.0.0"
}
]
}
]
}