CVE-2020-9314: XSS
PRODUCT NOT SUPPORTED WHEN ASSIGNED Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9314?
CVE-2020-9314 is classified as a medium severity vulnerability due to its potential for image injection in the Administration console.
How do I fix CVE-2020-9314?
To fix CVE-2020-9314, ensure that you upgrade Oracle iPlanet Web Server to a version later than 7.0.27.
What versions of Oracle iPlanet Web Server are affected by CVE-2020-9314?
CVE-2020-9314 affects Oracle iPlanet Web Server versions from 7.0.0 to 7.0.27.
Is CVE-2020-9314 patched?
CVE-2020-9314 is not patched as Oracle iPlanet Web Server 7.0.x is no longer supported.
What type of attack does CVE-2020-9314 enable?
CVE-2020-9314 enables an image injection attack through the productNameSrc parameter in the Administration console.