QID 376256

Date Published: 2022-01-19

QID 376256: Oracle Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities (CPUJAN2022)

Oracle HTTP Server is the Web server component for Oracle Fusion Middleware. It provides a listener for Oracle WebLogic Server and the framework for hosting static pages, dynamic pages, and applications over the Web.

Affected Versions:
12.2.1.3.0, 12.2.1.4.0, 12.2.1.5.0

QID Detection Logic (Authenticated):
This QID checks the vulnerable version of Oracle HTTP Server from file "inventory.xml" from the Home Directory.

Successful exploit could compromise Confidentiality, Integrity and Availability of the system

  • CVSS V3 rated as Critical - 9 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to vendor advisory Oracle HTTP Server JAN 2022

    CVEs related to QID 376256

    Software Advisories
    Advisory ID Software Component Link
    CPUJAN2022 URL Logo www.oracle.com/security-alerts/cpujan2022.html#AppendixFMW