Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73vm-8jvg-jpqh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

EPSS

Процентиль: 99%
0.8793
Высокий

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

CVSS3: 7.5
fstec
больше 5 лет назад

Уязвимость веб-сервера Oracle iPlanet, связанная с доступом для чтения к ключам шифрования без аутентификации, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 99%
0.8793
Высокий

Дефекты

CWE-326