CVE-2020-2952: Medium severity oracle http server vulnerability
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data as well as unauthorized read access to a subset of Oracle HTTP Server accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-2952.
What is the affected software?
The affected software is Oracle HTTP Server version 11.1.1.9.0.
How severe is this vulnerability?
This vulnerability has a severity rating of 6.5 (medium).
How can this vulnerability be exploited?
This vulnerability can be exploited by an unauthenticated attacker with network access via HTTP.
How can I fix this vulnerability?
To fix this vulnerability, you should apply the necessary patches provided by Oracle.