CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2020-13956: httpclient before 4.5.13 (exclusive), from 5.0.0 (inclusive), before 5.0.3 (exclusive); +17 more affected products

CVE-2020-13956. CVSS 3.1 base score 5.3 (MEDIUM, NVD). EPSS 0.09032 (percentile 0.95163), scored 2026-10-08.

Affected technology

httpclient · before 4.5.13 (exclusive)
apache

httpclient · from 5.0.0 (inclusive), before 5.0.3 (exclusive)
apache

quarkus · before 1.7.6 (exclusive)
quarkus

data integrator · 12.2.1.3.0
oracle

data integrator · 12.2.1.4.0
oracle

jd edwards enterpriseone orchestrator · before 9.2.6.0 (exclusive)
oracle

jd edwards enterpriseone tools · before 9.2.6.0 (exclusive)
oracle

nosql database · before 20.3 (exclusive)
oracle

peoplesoft enterprise peopletools · 8.57
oracle

peoplesoft enterprise peopletools · 8.58
oracle

peoplesoft enterprise pt peopletools · 8.57
oracle

peoplesoft enterprise pt peopletools · 8.58
oracle

peoplesoft enterprise pt peopletools · 8.59
oracle

primavera unifier · from 17.7 (inclusive), through 17.12 (inclusive)
oracle

primavera unifier · 16.1
oracle

primavera unifier · 16.2
oracle

primavera unifier · 18.8
oracle

primavera unifier · 19.12
oracle

primavera unifier · 20.12
oracle

retail customer management and segmentation foundation · from 16.0 (inclusive), through 19.0 (inclusive)
oracle

spatial studio · before 20.1.1 (exclusive)
oracle

sql developer · before 20.4.1.407.0006 (exclusive)
oracle

active iq unified manager · Version not applicable in the source CPE
netapp

snapcenter · Version not applicable in the source CPE
netapp

commerce guided search · 11.3.2
oracle

communications cloud native core service communication proxy · 1.14.0
oracle

sql developer · before 21.99 (exclusive)
oracle

weblogic server · 12.2.1.4.0
oracle

weblogic server · 14.1.1.0.0
oracle

Apache HttpClient · 4.5.12 and prior, 5.0.2 and prior
Vendor not specified by the source

Description’s affected range: versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

NVD’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality and availability impact as none; integrity impact as low. Source advisory’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality and availability impact as none; integrity impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-20
CCR priority
23.5 /100 (P4)
CVSS 3.1
5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N · NVD
EPSS
0.09032 · percentile 0.95163 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2020-13956.html