Vulnerability record · CVE-2020-9315 · published 10 May 2020
CVE-2020-9315: Oracle iPlanet Web Server admin console missing authentication exposes keys
Oracle · Iplanet Web Server
Oracle iPlanet Web Server 7.0.x has incorrect access control in the Administration console for admingui/version URIs, allowing unauthenticated read access to encryption keys. The product is marked as not supported when the CVE was assigned, so no vendor fix is expected. Exposure of encryption keys undermines the confidentiality of data the server protects.
Description
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network access to encryption keys is a serious confidentiality loss, and the product is unsupported with no patch path, though there is no confirmed in-the-wild exploitation.
What it is
Oracle iPlanet Web Server 7.0.x has incorrect access control in the Administration console for admingui/version URIs, allowing unauthenticated read access to encryption keys. The product is marked as not supported when the CVE was assigned, so no vendor fix is expected. Exposure of encryption keys undermines the confidentiality of data the server protects.
Impact
An unauthenticated attacker can read encryption keys from the administration console, which can enable decryption of protected data or further compromise of the server's trust material.
Attack surface
Reachable over the network via the administration console's admingui/version URIs; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is very high (0.81814, 99.6th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- There is no supported patch: Oracle lists iPlanet Web Server as not supported, so plan migration to a supported web server or Oracle replacement product.
- If the administration console must remain reachable, restrict it to trusted management networks and block admingui/version URIs at the reverse proxy or firewall.
- Rotate any encryption keys or certificates that may have been exposed through the console.
- Monitor the vendor lifetime-support references for any change in support status before assuming a fix will arrive.
Detection
- Alert on unauthenticated requests to /admingui/version or similar administration console URIs in web server and proxy logs.
- Baseline normal administration console access and flag requests from unexpected source IPs or without a prior authentication event.
- Review key material access and usage logs for signs that exposed keys were used outside expected systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2020/May/31 | Mailing ListThird Party Advisory |
| https://www.oracle.com/support/lifetime-support/ | Vendor Advisory |
| https://www.oracle.com/us/assets/lifetime-support-middleware-069163.pdf | Vendor Advisory |
| https://wwws.nightwatchcybersecurity.com/2020/05/10/two-vulnerabilities-in-oracles-iplanet-web-server-cve-2020-9315-and- | Third Party Advisory |
| http://seclists.org/fulldisclosure/2020/May/31 | Mailing ListThird Party Advisory |
| https://www.oracle.com/support/lifetime-support/ | Vendor Advisory |
| https://www.oracle.com/us/assets/lifetime-support-middleware-069163.pdf | Vendor Advisory |
| https://wwws.nightwatchcybersecurity.com/2020/05/10/two-vulnerabilities-in-oracles-iplanet-web-server-cve-2020-9315-and- | Third Party Advisory |
Track CVE-2020-9315 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-9315), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.