Vulnerabilities > Oracle > Iplanet WEB Server > 7.0.27

DATE CVE VULNERABILITY TITLE RISK
2020-05-10 CVE-2020-9315 Missing Authentication for Critical Function vulnerability in Oracle Iplanet web Server 7.0/7.0.27
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys.
network
low complexity
oracle CWE-306
7.5
2020-05-10 CVE-2020-9314 Cross-site Scripting vulnerability in Oracle Iplanet web Server 7.0/7.0.27
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI.
network
low complexity
oracle CWE-79
4.8