Iplanet's vulnerability profile centers on a legacy suite of web and application server products that were widely deployed in enterprise environments, including its web server, calendar server, and enterprise server platforms. The durable signal reflects the vendor's web-facing infrastructure role, with recurrent weaknesses including cross-site scripting and input-handling issues characteristic of server-side web applications, alongside a moderate tendency toward public exploit availability. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iplanet over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0746HIGH Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code v | Oct 18, 2001 | 10.0 | 42 | NO | YES |
CVE-2002-0845HIGH Buffer overflow in Sun ONE / iPlanet Web Server 4.1 and 6.0 allows remote attackers to execute arbitrary code via an HTTP request using chunked transfer encoding. | Aug 12, 2002 | 7.5 | 30 | NO | NO |
CVE-2001-0431HIGH Vulnerability in iPlanet Web Server Enterprise Edition 4.x. | Jul 2, 2001 | 10.0 | 27 | NO | NO |
CVE-2002-0686HIGH Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS- | Jul 23, 2002 | 7.5 | 25 | NO | NO |
CVE-2001-0747HIGH Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of service and possibly execute arbitrary c | Oct 18, 2001 | 7.5 | 25 | NO | NO |
CVE-2000-1077HIGH Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension. | Dec 11, 2000 | 10.0 | 25 | NO | NO |
CVE-2002-1316MEDIUM importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and | Nov 29, 2002 | 6.8 | 23 | NO | NO |
CVE-2002-1654HIGH iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher co | Dec 31, 2002 | 7.5 | 20 | NO | NO |
CVE-2001-0327MEDIUM iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encod | Jul 2, 2001 | 5.0 | 20 | NO | NO |
CVE-2002-1315MEDIUM Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrat | Nov 29, 2002 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iplanet.
Media articles that mention a CVE ID that affects a product developed by Iplanet — matched by CVE ID, not by vendor name.