CVE-2020-9315 Scanner
Detects 'Improper Access Control' vulnerability in Oracle iPlanet Web Server affects v. 7.0.x.
Short Info
Level
High
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
15 seconds
Time Interval
29 days
Scan only one
URL
Toolbox
-
Oracle iPlanet Web Server is a product that was used for web server and application server purposes. Developed by Oracle, it was designed to handle a wide range of tasks such as serving media files, hosting complex applications, and running websites for businesses. It was a popular product due to its security and scalability features, but now it is no longer supported by the vendor.
CVE-2020-9315 is a vulnerability that was detected in Oracle iPlanet Web Server 7.0.x. The vulnerability relates to the incorrect access control for admingui/version URIs in the Administration console. This flaw allowed for unauthenticated read access to encryption keys. The root of this vulnerability lies in the poor access control mechanisms deployed within this version of the web server.
Exploitation of this vulnerability can lead to a serious compromise of sensitive information that is stored within the web server. Encryption keys can be read and used for malicious purposes, thereby putting the entire server at risk. Cybercriminals can use these communication keys to access sensitive data such as login details, personal information, and confidential business data. The exploitation of this vulnerability can lead to severe reputational and financial damage for businesses.
In conclusion, it's important to be aware of vulnerabilities in your digital assets. With the pro features of the s4e.io platform, businesses can easily and quickly learn about vulnerabilities in their web servers, applications, and other digital assets. By staying informed and implementing the right measures, businesses can protect themselves against potential risks and maintain their reputation and financial security.
REFERENCES
- http://seclists.org/fulldisclosure/2020/May/31
- https://www.oracle.com/support/lifetime-support/
- https://www.oracle.com/us/assets/lifetime-support-middleware-069163.pdf
- https://wwws.nightwatchcybersecurity.com/2020/05/10/two-vulnerabilities-in-oracles-iplanet-web-server-cve-2020-9315-and-cve-2020-9314/