Vulnerabilities > Oracle > Iplanet WEB Server > 7.0.27

DATE CVE VULNERABILITY TITLE RISK
2020-05-10 CVE-2020-9315 Inadequate Encryption Strength vulnerability in Oracle Iplanet web Server 7.0/7.0.27
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys.
network
low complexity
oracle CWE-326
5.0
2020-05-10 CVE-2020-9314 Injection vulnerability in Oracle Iplanet web Server 7.0/7.0.27
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI.
network
oracle CWE-74
4.9