CVE-2020-2545
MEDIUMOracle HTTP Server 11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0 - Unauthenticated Partial Denial of Service via HTTPS
Title source: llmDescription
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2020.html
Scores
CVSS v3
5.3
EPSS
0.0149
EPSS Percentile
71.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
Status
published
Products (3)
oracle/http_server
11.1.1.9.0
oracle/http_server
12.1.3.0.0
oracle/http_server
12.2.1.3.0
Published
Jan 15, 2020
Tracked Since
Feb 18, 2026