First published: Wed Jan 15 2020(Updated: )
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle HTTP Server | =11.1.1.9.0 | |
Oracle HTTP Server | =12.1.3.0.0 | |
Oracle HTTP Server | =12.2.1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-2545 is medium with a CVSS score of 5.3.
The affected software for CVE-2020-2545 is Oracle HTTP Server versions 11.1.1.9.0, 12.1.3.0.0, and 12.2.1.3.0.
Yes, CVE-2020-2545 is an easily exploitable vulnerability.
An unauthenticated attacker with network access via HTTPS can exploit CVE-2020-2545 to compromise Oracle HTTP Server.
You can find more information about CVE-2020-2545 on the Oracle Security Alerts page: https://www.oracle.com/security-alerts/cpujan2020.html