Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-13956


Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.


Published

2020-12-02T17:15:14.547

Last Modified

2024-11-21T05:02:13.933

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache httpclient < 4.5.13 Yes
Application apache httpclient < 5.0.3 Yes
Application quarkus quarkus < 1.7.6 Yes
Application oracle data_integrator 12.2.1.3.0 Yes
Application oracle data_integrator 12.2.1.4.0 Yes
Application oracle jd_edwards_enterpriseone_orchestrator < 9.2.6.0 Yes
Application oracle jd_edwards_enterpriseone_tools < 9.2.6.0 Yes
Application oracle nosql_database < 20.3 Yes
Application oracle peoplesoft_enterprise_peopletools 8.57 Yes
Application oracle peoplesoft_enterprise_peopletools 8.58 Yes
Application oracle peoplesoft_enterprise_pt_peopletools 8.57 Yes
Application oracle peoplesoft_enterprise_pt_peopletools 8.58 Yes
Application oracle peoplesoft_enterprise_pt_peopletools 8.59 Yes
Application oracle primavera_unifier ≤ 17.12 Yes
Application oracle primavera_unifier 16.1 Yes
Application oracle primavera_unifier 16.2 Yes
Application oracle primavera_unifier 18.8 Yes
Application oracle primavera_unifier 19.12 Yes
Application oracle primavera_unifier 20.12 Yes
Application oracle retail_customer_management_and_segmentation_foundation ≤ 19.0 Yes
Application oracle spatial_studio < 20.1.1 Yes
Application oracle sql_developer < 20.4.1.407.0006 Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp snapcenter - Yes
Application oracle commerce_guided_search 11.3.2 Yes
Application oracle communications_cloud_native_core_service_communication_proxy 1.14.0 Yes
Application oracle sql_developer < 21.99 Yes
Application oracle weblogic_server 12.2.1.4.0 Yes
Application oracle weblogic_server 14.1.1.0.0 Yes

References