Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE network
low complexity
oracle
nessus
Published: 2020-01-15
Updated: 2021-09-22
Summary
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data as well as unauthorized read access to a subset of Oracle HTTP Server accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Vulnerable Configurations
Part | Description | Count |
Application | Oracle | 3 |
Nessus
NASL family | Web Servers |
NASL id | ORACLE_HTTP_SERVER_CPU_JAN_2020.NASL |
description | The version of Oracle HTTP Server installed on the remote host is affected by the following vulnerabilities as noted in the January 2020 CPU advisory : - An authentication bypass vulnerability exists in the web listener component. An unauthenticated, remote attacker can exploit this via HTTPS to gain unauthorized read, update, insert, delete access to a subset of Oracle HTTP Server accessible data. (CVE-2020-2530) - A Denial of Service (DoS) vulnerability exists in the SSL API component of the Oracle Security Service. An unauthenticated, remote attacker can exploit this via HTTPS to cause a partial DoS. (CVE-2020-2545) |
last seen | 2020-03-18 |
modified | 2020-01-21 |
plugin id | 133146 |
published | 2020-01-21 |
reporter | This script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/133146 |
title | Oracle Fusion Middleware Oracle HTTP Server (Jan 2020 CPU) |