PT-2020-5388 · Oracle · Oracle Iplanet Web Server

Published

2020-05-10

·

Updated

2021-07-21

·

CVE-2020-9315

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle iPlanet Web Server version 7.0.x
Description The issue is related to incorrect access control in the Oracle iPlanet Web Server, allowing unauthenticated read access to encryption keys. This can enable a remote attacker to disclose protected information. The vulnerability is demonstrated by unauthenticated read access to encryption keys through the admingui/version URIs in the Administration console.
Recommendations For Oracle iPlanet Web Server version 7.0.x, consider restricting access to the admingui/version URIs in the Administration console to prevent unauthenticated read access to encryption keys until a fix is available. As a temporary workaround, limit access to the Administration console to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Missing Authentication

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00434
BDU:2021-00475
CVE-2020-9315

Affected Products

Oracle Iplanet Web Server