5.3

CVE-2020-13956

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHttpclient Version < 4.5.13
ApacheHttpclient Version >= 5.0.0 < 5.0.3
QuarkusQuarkus Version < 1.7.6
OracleData Integrator Version12.2.1.3.0
OracleData Integrator Version12.2.1.4.0
OracleJd Edwards Enterpriseone Tools Version < 9.2.6.0
OracleNosql Database Version < 20.3
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OracleSpatial Studio Version < 20.1.1
OracleSql Developer Version < 20.4.1.407.0006
NetappActive Iq Unified Manager Version- SwPlatformlinux
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
NetappActive Iq Unified Manager Version- SwPlatformwindows
NetappSnapcenter Version-
OracleCommerce Guided Search Version11.3.2
OracleSql Developer Version < 21.99
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.652
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N