CVE-2020-9315: High severity iplanet web server vulnerability
PRODUCT NOT SUPPORTED WHEN ASSIGNED Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9315?
CVE-2020-9315 is classified as a high severity vulnerability due to its access control issues allowing unauthenticated access.
How do I fix CVE-2020-9315?
To fix CVE-2020-9315, you should upgrade to a supported version of Oracle iPlanet Web Server that has addressed this vulnerability.
What are the potential impacts of CVE-2020-9315?
The impacts of CVE-2020-9315 include unauthorized access to sensitive information, such as encryption keys, which can lead to further exploitation.
Is Oracle iPlanet Web Server 7.0.x still supported after CVE-2020-9315?
No, Oracle iPlanet Web Server 7.0.x is not supported following the identification of CVE-2020-9315.
Can CVE-2020-9315 be exploited remotely?
Yes, CVE-2020-9315 can be exploited remotely due to the incorrect access control in the Administration console.