PT-2020-5394 · Oracle · Oracle Iplanet Web Server
Published
2020-05-10
·
Updated
2021-07-21
·
CVE-2020-9314
CVSS v2.0
4.9
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle iPlanet Web Server versions 7.0.x
Description
The issue exists due to an incomplete fix, allowing an attacker to inject images into the administration console. This can be achieved through the
productNameSrc parameter in the admingui URI. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.Recommendations
For Oracle iPlanet Web Server versions 7.0.x, consider restricting access to the
admingui URI to minimize the risk of exploitation. Avoid using the productNameSrc parameter in the affected URI until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Special Elements Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Iplanet Web Server