Home / CVE DB / CVE-2020-13956
Standard
Vulnerability Identifier

CVE-2020-13956

2020-12-02
Severity Assessment
5.3
MEDIUM
CVSS v3.x Score
Clinical Analysis (Description)

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Vector Sequencing

Attack Parameters

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Impact Consequences

Technical Impact

Unchanged
Scope
None
Confidentiality
Low
Integrity
None
Availability
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v2 Score (Legacy)
5.0

For backward compatibility

EPSS Probability
0.51%

Percentile: 66.2%

Weakness Classification

CWE-NVD-CWE-noinfo

Affected Population

Affected Configurations

Total: 153 detected entries

Software List Scrollable
or
sql_developer
Vendor: oracle • v20.4.1.407.0006
or
retail_customer_management_and_segmentation_foundation
Vendor: oracle • v19.0
or
jd_edwards_enterpriseone_orchestrator
Vendor: oracle • v9.2.5.1
or
peoplesoft_enterprise_pt_peopletools
Vendor: oracle • v8.59
or
retail_customer_management_and_segmentation_foundation
Vendor: oracle • v16.0.2
or
primavera_unifier
Vendor: oracle • v17.10
ap
httpclient
Vendor: apache • v4.1
qu
quarkus
Vendor: quarkus • v0.23.0
or
jd_edwards_enterpriseone_orchestrator
Vendor: oracle • v9.2.4.2
ap
httpclient
Vendor: apache • v5.0.1
ap
httpclient
Vendor: apache • v4.1.2
qu
quarkus
Vendor: quarkus • v0.28.1
qu
quarkus
Vendor: quarkus • v0.7.0
or
primavera_unifier
Vendor: oracle • v17.9
ne
active_iq_unified_manager
Vendor: netapp • v-
qu
quarkus
Vendor: quarkus • v0.13.0
or
primavera_unifier
Vendor: oracle • v16.2
qu
quarkus
Vendor: quarkus • v0.22.0
qu
quarkus
Vendor: quarkus • v0.13.2
qu
quarkus
Vendor: quarkus • v0.12.0
qu
quarkus
Vendor: quarkus • v1.5.0
ap
httpclient
Vendor: apache • v5.0.0
qu
quarkus
Vendor: quarkus • v1.7.3
ap
httpclient
Vendor: apache • v4.5.11
ap
httpclient
Vendor: apache • v4.1.1
ap
httpclient
Vendor: apache • v4.2.1
qu
quarkus
Vendor: quarkus • v0.21.0
or
primavera_unifier
Vendor: oracle • v17.11
qu
quarkus
Vendor: quarkus • v0.23.1
or
jd_edwards_enterpriseone_tools
Vendor: oracle • v9.2.5.3
or
retail_customer_management_and_segmentation_foundation
Vendor: oracle • v17.0.1
or
peoplesoft_enterprise_peopletools
Vendor: oracle • v8.57
qu
quarkus
Vendor: quarkus • v0.21.1
or
jd_edwards_enterpriseone_orchestrator
Vendor: oracle • v9.2
qu
quarkus
Vendor: quarkus • v0.23.2
ap
httpclient
Vendor: apache • v4.5.8
or
jd_edwards_enterpriseone_tools
Vendor: oracle • v9.2
qu
quarkus
Vendor: quarkus • v1.7.2
qu
quarkus
Vendor: quarkus • v0.28.0
qu
quarkus
Vendor: quarkus • v0.2.0
qu
quarkus
Vendor: quarkus • v1.6.0
or
retail_customer_management_and_segmentation_foundation
Vendor: oracle • v16.0
qu
quarkus
Vendor: quarkus • v0.18.0
qu
quarkus
Vendor: quarkus • v0.5.0
ap
httpclient
Vendor: apache • v4.3.3
ne
snapcenter
Vendor: netapp • v-
or
peoplesoft_enterprise_pt_peopletools
Vendor: oracle • v8.57
ap
httpclient
Vendor: apache • v4.3.2
ap
httpclient
Vendor: apache • v4.5.12
qu
quarkus
Vendor: quarkus • v1.3.1
or
sql_developer
Vendor: oracle • v12.1.0.2
qu
quarkus
Vendor: quarkus • v0.3.0
qu
quarkus
Vendor: quarkus • v0.21.2
qu
quarkus
Vendor: quarkus • v0.0.1
or
jd_edwards_enterpriseone_tools
Vendor: oracle • v9.2.0.0
qu
quarkus
Vendor: quarkus • v0.4.0
or
spatial_studio
Vendor: oracle • v19.1.0
or
primavera_unifier
Vendor: oracle • v17.8
qu
quarkus
Vendor: quarkus • v0.15.0
qu
quarkus
Vendor: quarkus • v1.3.4
qu
quarkus
Vendor: quarkus • v1.1.1
or
peoplesoft_enterprise_peopletools
Vendor: oracle • v8.58
qu
quarkus
Vendor: quarkus • v0.11.0
ap
httpclient
Vendor: apache • v4.3.4
or
jd_edwards_enterpriseone_orchestrator
Vendor: oracle • v9.2.5.0
qu
quarkus
Vendor: quarkus • v1.4.1
ap
httpclient
Vendor: apache • v4.3.1
ap
httpclient
Vendor: apache • v4.5.6
qu
quarkus
Vendor: quarkus • v0.9.1
or
retail_customer_management_and_segmentation_foundation
Vendor: oracle • v18.0
ap
httpclient
Vendor: apache • v4.5.10
qu
quarkus
Vendor: quarkus • v0.26.0
or
data_integrator
Vendor: oracle • v12.2.1.4.0
qu
quarkus
Vendor: quarkus • v0.13.1
or
primavera_unifier
Vendor: oracle • v19.12
or
retail_customer_management_and_segmentation_foundation
Vendor: oracle • v16.0.1
or
communications_cloud_native_core_service_communication_proxy
Vendor: oracle • v1.14.0
qu
quarkus
Vendor: quarkus • v1.5.1
qu
quarkus
Vendor: quarkus • v1.4.2
qu
quarkus
Vendor: quarkus • v0.19.1
qu
quarkus
Vendor: quarkus • v0.24.0
qu
quarkus
Vendor: quarkus • v0.14.0
ap
httpclient
Vendor: apache • v4.2.3
qu
quarkus
Vendor: quarkus • v1.1.0
qu
quarkus
Vendor: quarkus • v1.4.0
ap
httpclient
Vendor: apache • v5.0.2
qu
quarkus
Vendor: quarkus • v0.10.0
ap
httpclient
Vendor: apache • v4.5.2
or
jd_edwards_enterpriseone_tools
Vendor: oracle • v9.1
or
primavera_unifier
Vendor: oracle • v17.7
qu
quarkus
Vendor: quarkus • v0.26.1
ap
httpclient
Vendor: apache • v4.5.9
qu
quarkus
Vendor: quarkus • v0.25.0
or
jd_edwards_enterpriseone_orchestrator
Vendor: oracle • v9.2.5.3
or
sql_developer
Vendor: oracle • v18c
qu
quarkus
Vendor: quarkus • v1.3.2
ap
httpclient
Vendor: apache • v4.3.5
qu
quarkus
Vendor: quarkus • v0.16.1
ap
httpclient
Vendor: apache • v4.0.1
qu
quarkus
Vendor: quarkus • v0.17.0
qu
quarkus
Vendor: quarkus • v1.2.1
qu
quarkus
Vendor: quarkus • v1.3.0
qu
quarkus
Vendor: quarkus • v0.19.0
or
data_integrator
Vendor: oracle • v12.2.1.3.0
or
weblogic_server
Vendor: oracle • v12.2.1.4.0
qu
quarkus
Vendor: quarkus • v1.7.4
qu
quarkus
Vendor: quarkus • v1.0.0
or
weblogic_server
Vendor: oracle • v14.1.1.0.0
qu
quarkus
Vendor: quarkus • v1.2.0
or
jd_edwards_enterpriseone_tools
Vendor: oracle • v9.1.5
qu
quarkus
Vendor: quarkus • v0.6.0
or
jd_edwards_enterpriseone_tools
Vendor: oracle • v4.0.1.0
qu
quarkus
Vendor: quarkus • v1.7.5
or
nosql_database
Vendor: oracle • v19.3.12
qu
quarkus
Vendor: quarkus • v1.0.1
or
jd_edwards_enterpriseone_tools
Vendor: oracle • v9.2.4.2
qu
quarkus
Vendor: quarkus • v0.9.0
or
retail_customer_management_and_segmentation_foundation
Vendor: oracle • v18.1
or
primavera_unifier
Vendor: oracle • v17.12
or
sql_developer
Vendor: oracle • v12.2.0.1
qu
quarkus
Vendor: quarkus • v0.16.0
qu
quarkus
Vendor: quarkus • v0.27.0
ap
httpclient
Vendor: apache • v4.5.4
ap
httpclient
Vendor: apache • v4.5.7
or
jd_edwards_enterpriseone_tools
Vendor: oracle • v9.2.4.0
ap
httpclient
Vendor: apache • v4.0
or
jd_edwards_enterpriseone_tools
Vendor: oracle • v8.98
or
primavera_unifier
Vendor: oracle • v20.12
or
primavera_unifier
Vendor: oracle • v16.1
ap
httpclient
Vendor: apache • v4.5.5
ap
httpclient
Vendor: apache • v4.2.2
qu
quarkus
Vendor: quarkus • v0.1.0
or
peoplesoft_enterprise_pt_peopletools
Vendor: oracle • v8.58
qu
quarkus
Vendor: quarkus • v1.5.2
or
jd_edwards_enterpriseone_tools
Vendor: oracle • v9.2.5.0
qu
quarkus
Vendor: quarkus • v0.8.0
ap
httpclient
Vendor: apache • v3.1
qu
quarkus
Vendor: quarkus • v0.13.3
qu
quarkus
Vendor: quarkus • v1.6.1
qu
quarkus
Vendor: quarkus • v1.7.1
or
retail_customer_management_and_segmentation_foundation
Vendor: oracle • v17.0
ap
httpclient
Vendor: apache • v4.4.1
qu
quarkus
Vendor: quarkus • v1.7.0
ap
httpclient
Vendor: apache • v4.5.3
ap
httpclient
Vendor: apache • v4.3
or
sql_developer
Vendor: oracle • v11.2.0.4
qu
quarkus
Vendor: quarkus • v0.20.0
qu
quarkus
Vendor: quarkus • v1.3.3
ap
httpclient
Vendor: apache • v4.2
ap
httpclient
Vendor: apache • v4.5
ap
httpclient
Vendor: apache • v4.5.1
or
primavera_unifier
Vendor: oracle • v18.8
or
commerce_guided_search
Vendor: oracle • v11.3.2
Timeline

Time Line

PUBLICATION
02 Dec 2020
MODIFICATION
01 Dec 2025
FIRST PATCH
21 Oct 2025
Impact Statistics

Key Metrics

CVSS Score
5.3
MEDIUM
Products
153
Affected
Patches
2
Available
Remediation Protocol

Recommended Solution

No automatic solution found. Check vendor references.
Recommended Actions for Administrators

Immediate Action Plan

1. Inventory

Identify all affected systems in your infrastructure.

2. Assessment

Assess exposure and criticality for your organization.

3. Mitigation

Apply patches or available workarounds.

4. Verification

Test and confirm effectiveness of applied measures.