CVE-2020-9488

Source
https://cve.org/CVERecord?id=CVE-2020-9488
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-9488.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-9488
Aliases
Downstream
Related
Published
2020-04-27T16:15:12.897Z
Modified
2026-06-18T03:55:02.734349596Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Database specific
{
    "unresolved_ranges": [
        {
            "vendor_product": "oracle:financial_services_analytical_applications_infrastructure",
            "extracted_events": [
                {
                    "introduced": "8.0.6.0.0"
                },
                {
                    "last_affected": "8.1.0.0.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "oracle:flexcube_core_banking",
            "extracted_events": [
                {
                    "introduced": "11.5.0"
                },
                {
                    "last_affected": "11.7.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:flexcube_core_banking:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "oracle:insurance_insbridge_rating_and_underwriting",
            "extracted_events": [
                {
                    "introduced": "5.0.0.0"
                },
                {
                    "last_affected": "5.6.0.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "oracle:policy_automation",
            "extracted_events": [
                {
                    "introduced": "12.2.0"
                },
                {
                    "last_affected": "12.2.20"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:policy_automation:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "oracle:policy_automation_for_mobile_devices",
            "extracted_events": [
                {
                    "introduced": "12.2.0"
                },
                {
                    "last_affected": "12.2.20"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:policy_automation_for_mobile_devices:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "oracle:siebel_apps_-_marketing",
            "extracted_events": [
                {
                    "last_affected": "21.9"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:siebel_apps_-_marketing:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "oracle:siebel_ui_framework",
            "extracted_events": [
                {
                    "last_affected": "21.2"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "oracle:utilities_framework",
            "extracted_events": [
                {
                    "introduced": "4.3.0.1.0"
                },
                {
                    "last_affected": "4.3.0.6.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:utilities_framework:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "debian:debian_linux",
            "extracted_events": [
                {
                    "last_affected": "9.0"
                },
                {
                    "last_affected": "10.0"
                },
                {
                    "last_affected": "11.0"
                }
            ],
            "cpes": [
                "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:communications_application_session_controller",
            "extracted_events": [
                {
                    "last_affected": "3.9m0p1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:communications_application_session_controller:3.9m0p1:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:communications_billing_and_revenue_management",
            "extracted_events": [
                {
                    "last_affected": "7.5.0.23.0"
                },
                {
                    "last_affected": "12.0.0.3.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:communications_eagle_ftp_table_base_retrieval",
            "extracted_events": [
                {
                    "last_affected": "4.5"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:communications_eagle_ftp_table_base_retrieval:4.5:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:communications_offline_mediation_controller",
            "extracted_events": [
                {
                    "last_affected": "12.0.0.3.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:communications_services_gatekeeper",
            "extracted_events": [
                {
                    "last_affected": "7.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:communications_services_gatekeeper:7.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:communications_unified_inventory_management",
            "extracted_events": [
                {
                    "last_affected": "7.3.0"
                },
                {
                    "last_affected": "7.4.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:data_integrator",
            "extracted_events": [
                {
                    "last_affected": "12.2.1.3.0"
                },
                {
                    "last_affected": "12.2.1.4.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:data_integrator:12.2.1.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:enterprise_manager_for_peoplesoft",
            "extracted_events": [
                {
                    "last_affected": "13.4.1.1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:enterprise_manager_for_peoplesoft:13.4.1.1:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:financial_services_institutional_performance_analytics",
            "extracted_events": [
                {
                    "last_affected": "8.0.6"
                },
                {
                    "last_affected": "8.1.0"
                },
                {
                    "last_affected": "8.7.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.0.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.1.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:financial_services_institutional_performance_analytics:8.7.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:financial_services_market_risk_measurement_and_management",
            "extracted_events": [
                {
                    "last_affected": "8.0.6"
                },
                {
                    "last_affected": "8.0.8"
                },
                {
                    "last_affected": "8.1.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.1.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:financial_services_price_creation_and_discovery",
            "extracted_events": [
                {
                    "last_affected": "8.0.6"
                },
                {
                    "last_affected": "8.0.7"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:financial_services_price_creation_and_discovery:8.0.7:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:financial_services_retail_customer_analytics",
            "extracted_events": [
                {
                    "last_affected": "8.0.6"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:financial_services_retail_customer_analytics:8.0.6:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:flexcube_core_banking",
            "extracted_events": [
                {
                    "last_affected": "5.2.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:flexcube_core_banking:5.2.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:flexcube_private_banking",
            "extracted_events": [
                {
                    "last_affected": "12.0.0"
                },
                {
                    "last_affected": "12.1.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:health_sciences_information_manager",
            "extracted_events": [
                {
                    "last_affected": "3.0.1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:health_sciences_information_manager:3.0.1:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:insurance_insbridge_rating_and_underwriting",
            "extracted_events": [
                {
                    "last_affected": "5.6.1.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:insurance_insbridge_rating_and_underwriting:5.6.1.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:insurance_policy_administration_j2ee",
            "extracted_events": [
                {
                    "last_affected": "10.2.0.37"
                },
                {
                    "last_affected": "10.2.4.12"
                },
                {
                    "last_affected": "11.0.2.25"
                },
                {
                    "last_affected": "11.1.0.15"
                },
                {
                    "last_affected": "11.2.0.26"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.0.37:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.4.12:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.0.2.25:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.1.0.15:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.2.0.26:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:insurance_rules_palette",
            "extracted_events": [
                {
                    "last_affected": "10.2.0.37"
                },
                {
                    "last_affected": "10.2.4.12"
                },
                {
                    "last_affected": "11.0.2.25"
                },
                {
                    "last_affected": "11.1.0.15"
                },
                {
                    "last_affected": "11.2.0.26"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:insurance_rules_palette:10.2.0.37:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:insurance_rules_palette:10.2.4.12:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:insurance_rules_palette:11.0.2.25:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:insurance_rules_palette:11.1.0.15:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:insurance_rules_palette:11.2.0.26:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:jd_edwards_world_security",
            "extracted_events": [
                {
                    "last_affected": "a9.4"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:oracle_goldengate_application_adapters",
            "extracted_events": [
                {
                    "last_affected": "19.1.0.0.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:oracle_goldengate_application_adapters:19.1.0.0.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:peoplesoft_enterprise_peopletools",
            "extracted_events": [
                {
                    "last_affected": "8.56"
                },
                {
                    "last_affected": "8.57"
                },
                {
                    "last_affected": "8.58"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:policy_automation_connector_for_siebel",
            "extracted_events": [
                {
                    "last_affected": "10.4.6"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:policy_automation_connector_for_siebel:10.4.6:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:primavera_unifier",
            "extracted_events": [
                {
                    "last_affected": "18.8"
                },
                {
                    "last_affected": "19.12"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:retail_advanced_inventory_planning",
            "extracted_events": [
                {
                    "last_affected": "14.1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:retail_advanced_inventory_planning:14.1:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:retail_assortment_planning",
            "extracted_events": [
                {
                    "last_affected": "15.0.3.0"
                },
                {
                    "last_affected": "16.0.3.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:retail_assortment_planning:15.0.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_assortment_planning:16.0.3.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:retail_bulk_data_integration",
            "extracted_events": [
                {
                    "last_affected": "15.0.3.0"
                },
                {
                    "last_affected": "16.0.3.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:retail_bulk_data_integration:15.0.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:retail_customer_management_and_segmentation_foundation",
            "extracted_events": [
                {
                    "last_affected": "16.0"
                },
                {
                    "last_affected": "17.0"
                },
                {
                    "last_affected": "18.0"
                },
                {
                    "last_affected": "19.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:16.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:17.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:retail_eftlink",
            "extracted_events": [
                {
                    "last_affected": "15.0.2"
                },
                {
                    "last_affected": "16.0.3"
                },
                {
                    "last_affected": "17.0.2"
                },
                {
                    "last_affected": "18.0.1"
                },
                {
                    "last_affected": "19.0.1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:retail_eftlink:15.0.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_eftlink:16.0.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_eftlink:17.0.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_eftlink:18.0.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_eftlink:19.0.1:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:retail_insights_cloud_service_suite",
            "extracted_events": [
                {
                    "last_affected": "19.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:retail_insights_cloud_service_suite:19.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:retail_integration_bus",
            "extracted_events": [
                {
                    "last_affected": "14.1"
                },
                {
                    "last_affected": "15.0"
                },
                {
                    "last_affected": "16.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:retail_integration_bus:14.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_integration_bus:15.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_integration_bus:16.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:retail_order_broker_cloud_service",
            "extracted_events": [
                {
                    "last_affected": "16.0"
                },
                {
                    "last_affected": "18.0"
                },
                {
                    "last_affected": "19.0"
                },
                {
                    "last_affected": "19.1"
                },
                {
                    "last_affected": "19.2"
                },
                {
                    "last_affected": "19.3"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:retail_order_broker_cloud_service:16.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_order_broker_cloud_service:18.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_order_broker_cloud_service:19.3:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:retail_predictive_application_server",
            "extracted_events": [
                {
                    "last_affected": "14.1.3.0"
                },
                {
                    "last_affected": "15.0.3.0"
                },
                {
                    "last_affected": "16.0.3.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:retail_predictive_application_server:14.1.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:retail_xstore_point_of_service",
            "extracted_events": [
                {
                    "last_affected": "15.0.4"
                },
                {
                    "last_affected": "16.0.6"
                },
                {
                    "last_affected": "17.0.4"
                },
                {
                    "last_affected": "18.0.3"
                },
                {
                    "last_affected": "19.0.2"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0.2:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:spatial_and_graph",
            "extracted_events": [
                {
                    "last_affected": "12.2.0.1"
                },
                {
                    "last_affected": "18c"
                },
                {
                    "last_affected": "19c"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:spatial_and_graph:12.2.0.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:spatial_and_graph:18c:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:spatial_and_graph:19c:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:storagetek_acsls",
            "extracted_events": [
                {
                    "last_affected": "8.5.1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:storagetek_acsls:8.5.1:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:storagetek_tape_analytics_sw_tool",
            "extracted_events": [
                {
                    "last_affected": "2.3.1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:storagetek_tape_analytics_sw_tool:2.3.1:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:utilities_framework",
            "extracted_events": [
                {
                    "last_affected": "2.2.0.0.0"
                },
                {
                    "last_affected": "4.2.0.2.0"
                },
                {
                    "last_affected": "4.2.0.3.0"
                },
                {
                    "last_affected": "4.4.0.0.0"
                },
                {
                    "last_affected": "4.4.0.2.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:utilities_framework:2.2.0.0.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:utilities_framework:4.2.0.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:utilities_framework:4.2.0.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:utilities_framework:4.4.0.0.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:utilities_framework:4.4.0.2.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:weblogic_server",
            "extracted_events": [
                {
                    "last_affected": "10.3.6.0.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        }
    ]
}
References

Affected packages

Git / github.com/apache/logging-log4j2

Affected ranges

Type
GIT
Repo
https://github.com/apache/logging-log4j2
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.0"
        },
        {
            "fixed": "2.3.2"
        },
        {
            "introduced": "2.4"
        },
        {
            "fixed": "2.12.3"
        },
        {
            "introduced": "2.13.0"
        },
        {
            "fixed": "2.13.2"
        }
    ],
    "cpe": "cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Affected versions

log4j-2.*
log4j-2.10-rc1
log4j-2.10.0
log4j-2.11.0
log4j-2.11.0-rc1
log4j-2.11.1
log4j-2.11.1-rc1
log4j-2.11.2
log4j-2.11.2-rc1
log4j-2.11.2-rc2
log4j-2.11.2-rc3
log4j-2.12.0
log4j-2.12.0-rc1
log4j-2.12.0-rc2
log4j-2.12.1
log4j-2.12.1-rc1
log4j-2.12.2-rc1
log4j-2.13.0-rc2
log4j-2.13.1
log4j-2.13.1-rc1
log4j-2.13.1-rc2
log4j-2.4
log4j-2.4.1
log4j-2.5
log4j-2.5-rc1
log4j-2.7
log4j-2.7-rc1
log4j-2.7-rc2
log4j-2.8
log4j-2.8-rc1
log4j-2.8.1
log4j-2.8.1-rc1
log4j-2.9-rc1
log4j-2.9.0
log4j-2.9.1-rc1
rel/2.*
rel/2.10.0
rel/2.11.0
rel/2.11.1
rel/2.11.2
rel/2.12.0
rel/2.12.1
rel/2.12.2
rel/2.13.0
rel/2.13.1
rel/2.4
rel/2.4.1
rel/2.5
rel/2.7
rel/2.8
rel/2.8.1
rel/2.9.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-9488.json"

Git / github.com/qos-ch/reload4j

Affected ranges

Type
GIT
Repo
https://github.com/qos-ch/reload4j
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.2.18.3"
        }
    ],
    "cpe": "cpe:2.3:a:qos:reload4j:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Affected versions

v1.*
v1.2.18.0
Other
v1_2_17
v_1.*
v_1.2.18.1
v_1.2.18.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-9488.json"