MEDIUM · 5.3

CVE-2020-13956

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host ...

Vulnerability Description

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
ApacheHttpclient< 4.5.13
QuarkusQuarkus< 1.7.6
OracleData Integrator12.2.1.3.0
OracleJd Edwards Enterpriseone Orchestrator< 9.2.6.0
OracleJd Edwards Enterpriseone Tools< 9.2.6.0
OracleNosql Database< 20.3
OraclePeoplesoft Enterprise Peopletools8.57
OraclePeoplesoft Enterprise Pt Peopletools8.57
OraclePrimavera Unifier>= 17.7, <= 17.12
OracleRetail Customer Management And Segmentation Foundation>= 16.0, <= 19.0
OracleSpatial Studio< 20.1.1
OracleSql Developer< 20.4.1.407.0006
NetappActive Iq Unified Manager-
NetappSnapcenter-
OracleCommerce Guided Search11.3.2
OracleCommunications Cloud Native Core Service Communication Proxy1.14.0
OracleWeblogic Server12.2.1.4.0

References

FAQ

What is CVE-2020-13956?

CVE-2020-13956 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host ...

How severe is CVE-2020-13956?

CVE-2020-13956 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-13956?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Httpclient, Quarkus Quarkus, Oracle Data Integrator, Oracle Jd Edwards Enterpriseone Orchestrator, Oracle Jd Edwards Enterpriseone Tools.