QID 159609

Date Published: 2022-02-23

QID 159609: Oracle Enterprise Linux Security Update for httpd:2.4 (ELSA-2022-9005)

Oracle Enterprise Linux has released a security update for httpd:2.4 to fix the vulnerabilities.

Affected Product:
Oracle Linux 8

This vulnerability could be exploited to gain partial access to sensitive information. Malicious users could also use this vulnerability to change partial contents or configuration on the system. Additionally this vulnerability can also be used to cause a limited denial of service in the form of interruptions in resource availability.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    To resolve this issue, upgrade to the latest packages which contain a patch. Refer to Oracle Enterprise Linux advisory below for updates and patch information:

    ELSA-2022-9005.
    Vendor References

    CVEs related to QID 159609

    Software Advisories
    Advisory ID Software Component Link
    ELSA-2022-9005 Oracle Linux URL Logo linux.oracle.com/errata/ELSA-2022-9005.html