Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NApache Httpclient
APPApache< 4.5.135.0.0 – 5.0.3 (bez)Netapp Active Iq Unified Manager
APPNetappwszystkie wersjeNetapp Snapcenter
APPNetappwszystkie wersjeOracle Commerce Guided Search
APPOracle11.3.2Oracle Communications Cloud Native Core Service Communication Proxy
APPOracle1.14.0Oracle Data Integrator
APPOracle12.2.1.3.012.2.1.4.0Oracle Jd Edwards Enterpriseone Orchestrator
APPOracle< 9.2.6.0Oracle Jd Edwards Enterpriseone Tools
APPOracle< 9.2.6.0Oracle Nosql Database
APPOracle< 20.3Oracle Peoplesoft Enterprise Peopletools
APPOracle8.578.58Oracle Peoplesoft Enterprise Pt Peopletools
APPOracle8.578.588.59Oracle Primavera Unifier
APPOracle16.116.218.819.1220.1217.7 – 17.12Oracle Retail Customer Management And Segmentation Foundation
APPOracle16.0 – 19.0Oracle Spatial Studio
APPOracle< 20.1.1Oracle Sql Developer
APPOracle< 20.4.1.407.0006< 21.99Oracle Weblogic Server
APPOracle12.2.1.4.014.1.1.0.0Quarkus
APPQuarkus< 1.7.6
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Referencje
Powiązane podatności
CVE-2026-35273CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Pominięcie uwierzytelnienia w Oracle PeopleSoft PeopleTools (RCE/Takeover)
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2022-22947CRITICAL10.0⚠ KEVPL ✓ten sam produkt
RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓ten sam produkt
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
CVE-2021-42013CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)