← Vulnerability feed

Vulnerability record · CVE-2020-9315 · published 10 May 2020

CVE-2020-9315: Oracle iPlanet Web Server admin console missing authentication exposes keys

Oracle · Iplanet Web Server

Oracle iPlanet Web Server 7.0.x has incorrect access control in the Administration console for admingui/version URIs, allowing unauthenticated read access to encryption keys. The product is marked as not supported when the CVE was assigned, so no vendor fix is expected. Exposure of encryption keys undermines the confidentiality of data the server protects.

7.5 CVSS 3.1 High EPSS 82% · top 0.4% CWE-306 · Missing authentication for critical function
7.5CVSS 3.1 base score, v2 5.0
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated network access to encryption keys is a serious confidentiality loss, and the product is unsupported with no patch path, though there is no confirmed in-the-wild exploitation.

What it is

Oracle iPlanet Web Server 7.0.x has incorrect access control in the Administration console for admingui/version URIs, allowing unauthenticated read access to encryption keys. The product is marked as not supported when the CVE was assigned, so no vendor fix is expected. Exposure of encryption keys undermines the confidentiality of data the server protects.

Impact

An unauthenticated attacker can read encryption keys from the administration console, which can enable decryption of protected data or further compromise of the server's trust material.

Attack surface

Reachable over the network via the administration console's admingui/version URIs; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is very high (0.81814, 99.6th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • There is no supported patch: Oracle lists iPlanet Web Server as not supported, so plan migration to a supported web server or Oracle replacement product.
  • If the administration console must remain reachable, restrict it to trusted management networks and block admingui/version URIs at the reverse proxy or firewall.
  • Rotate any encryption keys or certificates that may have been exposed through the console.
  • Monitor the vendor lifetime-support references for any change in support status before assuming a fix will arrive.

Detection

  • Alert on unauthenticated requests to /admingui/version or similar administration console URIs in web server and proxy logs.
  • Baseline normal administration console access and flag requests from unexpected source IPs or without a prior authentication event.
  • Review key material access and usage logs for signs that exposed keys were used outside expected systems.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-9315 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-7182Oracle traffic director memory buffer overflow vulnerabilityHeap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firef…EPSS 10%8.8CVE-2016-1950Mozilla network security services memory buffer overflow vulnerabilityHeap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox…EPSS 4.2%6.1CVE-2017-10055Oracle iplanet web server vulnerabilityVulnerability in the Oracle iPlanet Web Server component of Oracle Fusion Middleware (subcomponent: Admin Graphical User Interface). The supported ve…EPSS 1.4%5.0CVE-2012-1738Oracle iplanet web server vulnerabilityUnspecified vulnerability in the Oracle iPlanet Web Server component in Oracle Sun Products Suite Java System Web Server 6.1 and Oracle iPlanet Web S…EPSS 2.7%4.8CVE-2020-9314Oracle iplanet web server cross-site scripting vulnerability** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc…EPSS 1.3%4.3CVE-2013-1620Mozilla network security services observable discrepancy vulnerabilityThe TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check …EPSS 3.7%8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed

Source: NIST National Vulnerability Database (record CVE-2020-9315), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.