Update CVE-2020-9315.yaml

patch-1
Prince Chaddha 2022-06-28 08:37:51 +05:30 committed by GitHub
parent 772164de85
commit 3957ba18f8
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 2 deletions

View File

@ -4,7 +4,7 @@ info:
name: Oracle iPlanet Web Server 7.0.x - Authentication Bypass
author: dhiyaneshDk
severity: high
description: '** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has incorrect access control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.'
description: Oracle iPlanet Web Server 7.0.x has incorrect access control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.'
reference:
- https://www.cvebase.com/cve/2020/9315
- https://www.oracle.com/support/lifetime-support/
@ -16,7 +16,7 @@ info:
cvss-score: 7.5
cve-id: CVE-2020-9315
cwe-id: CWE-306
tags: cve,cve2020,oracle
tags: cve,cve2020,oracle,auth-bypass,iplanet
requests:
- method: GET