CVE-2020-9315
Oracle iPlanet Web Server 7.0.x - Authentication Bypass
Record summary
CVE-2020-9315 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHOracle iPlanet Web Server 7.0.x - Authentication BypassCVSS 7.5
Oracle iPlanet Web Server 7.0.x has incorrect access control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE a related support policy can be found in the www.oracle.com references attached to this CVE.
Impact
Successful exploitation of this vulnerability allows an attacker to bypass authentication and gain unauthorized access to the affected system.
Remediation
Apply the necessary patches or updates provided by Oracle to mitigate this vulnerability.
Source: ProjectDiscovery