QID 375965

Date Published: 2022-01-03

QID 375965: Oracle Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities (CPUOCT2021)

Oracle HTTP Server is the Web server component for Oracle Fusion Middleware. It provides a listener for Oracle WebLogic Server and the framework for hosting static pages, dynamic pages, and applications over the Web.

Affected Versions:
Oracle HTTP Server, versions 11.1.1.9.0, 12.2.1.4.0, 12.2.1.3.0

QID Detection Logic (Authenticated):
This QID checks the vulnerable version of Oracle HTTP Server from file "inventory.xml" from the Home Directory.

Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.1 severity.
  • Solution
    Refer to vendor advisory Oracle HTTP Server OCT 2021

    CVEs related to QID 375965

    Software Advisories
    Advisory ID Software Component Link
    CPUOCT2021 Linux URL Logo www.oracle.com/security-alerts/cpuoct2021.html#AppendixOVIR
    CPUOCT2021 Windows URL Logo www.oracle.com/security-alerts/cpuoct2021.html#AppendixOVIR