Record summary

CVE-2020-9315 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHOracle iPlanet Web Server 7.0.x - Authentication BypassCVSS 7.5

Oracle iPlanet Web Server 7.0.x has incorrect access control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE a related support policy can be found in the www.oracle.com references attached to this CVE.

Impact

Successful exploitation of this vulnerability allows an attacker to bypass authentication and gain unauthorized access to the affected system.

Remediation

Apply the necessary patches or updates provided by Oracle to mitigate this vulnerability.

WeaknessesCWE-306
AuthorsdhiyaneshDk
Template tagscvecve2020oracleauth-bypassiplanetvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:oracle:iplanet_web_server:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:oracle:iplanet_web_server"

Source: ProjectDiscovery

References

5