MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2020-13956

CVSS 5.3v3.1pub. 2020-12-02upd. 2025-12-01

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  • Apache Httpclient

    APP
    Apache
    < 4.5.135.0.0 – 5.0.3 (excl.)
  • Netapp Active Iq Unified Manager

    APP
    Netapp
    all versions
  • Netapp Snapcenter

    APP
    Netapp
    all versions
  • Oracle Commerce Guided Search

    APP
    Oracle
    11.3.2
  • Oracle Communications Cloud Native Core Service Communication Proxy

    APP
    Oracle
    1.14.0
  • Oracle Data Integrator

    APP
    Oracle
    12.2.1.3.012.2.1.4.0
  • Oracle Jd Edwards Enterpriseone Orchestrator

    APP
    Oracle
    < 9.2.6.0
  • Oracle Jd Edwards Enterpriseone Tools

    APP
    Oracle
    < 9.2.6.0
  • Oracle Nosql Database

    APP
    Oracle
    < 20.3
  • Oracle Peoplesoft Enterprise Peopletools

    APP
    Oracle
    8.578.58
  • Oracle Peoplesoft Enterprise Pt Peopletools

    APP
    Oracle
    8.578.588.59
  • Oracle Primavera Unifier

    APP
    Oracle
    16.116.218.819.1220.1217.7 – 17.12
  • Oracle Retail Customer Management And Segmentation Foundation

    APP
    Oracle
    16.0 – 19.0
  • Oracle Spatial Studio

    APP
    Oracle
    < 20.1.1
  • Oracle Sql Developer

    APP
    Oracle
    < 20.4.1.407.0006< 21.99
  • Oracle Weblogic Server

    APP
    Oracle
    12.2.1.4.014.1.1.0.0
  • Quarkus

    APP
    Quarkus
    < 1.7.6
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-35273CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelnienia w Oracle PeopleSoft PeopleTools (RCE/Takeover)

CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product

Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+

CVE-2022-22947CRITICAL10.0⚠ KEVPL ✓same product

RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup

CVE-2021-42013CRITICAL9.8⚠ KEVPL ✓same product

Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)