S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-9315 Scanner

Detects 'Improper Access Control' vulnerability in Oracle iPlanet Web Server affects v. 7.0.x.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-9315
7.5
CVSS

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Oracle iPlanet Web Server is a product that was used for web server and application server purposes. Developed by Oracle, it was designed to handle a wide range of tasks such as serving media files, hosting complex applications, and running websites for businesses. It was a popular product due to its security and scalability features, but now it is no longer supported by the vendor. 

CVE-2020-9315 is a vulnerability that was detected in Oracle iPlanet Web Server 7.0.x. The vulnerability relates to the incorrect access control for admingui/version URIs in the Administration console. This flaw allowed for unauthenticated read access to encryption keys. The root of this vulnerability lies in the poor access control mechanisms deployed within this version of the web server. 

Exploitation of this vulnerability can lead to a serious compromise of sensitive information that is stored within the web server. Encryption keys can be read and used for malicious purposes, thereby putting the entire server at risk. Cybercriminals can use these communication keys to access sensitive data such as login details, personal information, and confidential business data. The exploitation of this vulnerability can lead to severe reputational and financial damage for businesses. 

In conclusion, it's important to be aware of vulnerabilities in your digital assets. With the pro features of the s4e.io platform, businesses can easily and quickly learn about vulnerabilities in their web servers, applications, and other digital assets. By staying informed and implementing the right measures, businesses can protect themselves against potential risks and maintain their reputation and financial security.

 

REFERENCES

Solution Advice

Precautions can be taken to protect against this vulnerability by implementing the following bullet-list measures:

  • Oracle iPlanet Web Server is not supported by the vendor anymore. Replace with an appropriate Web Server immediately. Until that time,
  • Ensure that access controls are set up correctly to limit access to the Administration console and other critical areas of the web server.
  • Review web server access logs for any suspicious activity that could indicate attempted exploitation of the vulnerability.
  • Store encryption keys in a secure location and provide access to a limited number of authorized individuals.
  • Implement additional security measures such as monitoring tools, firewalls, and regular security assessments.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-9315 scanner - Improper Access Control vulnerability in Oracle iPlanet Web Server | S4E