Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NApache Httpclient
APPApache< 4.5.135.0.0 – 5.0.3 (excl.)Netapp Active Iq Unified Manager
APPNetappall versionsNetapp Snapcenter
APPNetappall versionsOracle Commerce Guided Search
APPOracle11.3.2Oracle Communications Cloud Native Core Service Communication Proxy
APPOracle1.14.0Oracle Data Integrator
APPOracle12.2.1.3.012.2.1.4.0Oracle Jd Edwards Enterpriseone Orchestrator
APPOracle< 9.2.6.0Oracle Jd Edwards Enterpriseone Tools
APPOracle< 9.2.6.0Oracle Nosql Database
APPOracle< 20.3Oracle Peoplesoft Enterprise Peopletools
APPOracle8.578.58Oracle Peoplesoft Enterprise Pt Peopletools
APPOracle8.578.588.59Oracle Primavera Unifier
APPOracle16.116.218.819.1220.1217.7 – 17.12Oracle Retail Customer Management And Segmentation Foundation
APPOracle16.0 – 19.0Oracle Spatial Studio
APPOracle< 20.1.1Oracle Sql Developer
APPOracle< 20.4.1.407.0006< 21.99Oracle Weblogic Server
APPOracle12.2.1.4.014.1.1.0.0Quarkus
APPQuarkus< 1.7.6
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
References
Related vulnerabilities
CVE-2026-35273CRITICAL9.8⚠ KEVPL ✓same product
Pominięcie uwierzytelnienia w Oracle PeopleSoft PeopleTools (RCE/Takeover)
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2022-22947CRITICAL10.0⚠ KEVPL ✓same product
RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
CVE-2021-42013CRITICAL9.8⚠ KEVPL ✓same product
Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)