CVE-2020-9314 is an image injection vulnerability in Oracle iPlanet Web Server 7.0.x, specifically within the Administration console via the productNameSrc parameter. This medium-severity vulnerability (CVSS 4.8) requires high privileges and user interaction, allowing an attacker to inject images with potential impacts on confidentiality and integrity. Although not listed in CISA KEV, Nuclei templates exist for this flaw, and it has garnered some community discussion, indicating awareness among security researchers. This issue is a regression of an incomplete fix for CVE-2012-0516.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0, <= 7.0.27CPE matchmatch criteria | cpe:2.3:a:oracle:iplanet_web_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.