QID 376737

Date Published: 2022-07-20

QID 376737: Oracle Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities (CPUJUL2022)

Oracle HTTP Server is the Web server component for Oracle Fusion Middleware. It provides a listener for Oracle WebLogic Server and the framework for hosting static pages, dynamic pages, and applications over the Web.

Affected Versions:
Oracle HTTP Server, versions 12.2.1.3.0, 12.2.1.4.0

QID Detection Logic (Authenticated):
This QID checks the vulnerable version of Oracle HTTP Server from file "inventory.xml" from the Home Directory.

Successful exploitation could compromise integrity, availability and confidentiality

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Refer to vendor advisory Oracle HTTP Server JUL 2021
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    cpujul2022 URL Logo www.oracle.com/security-alerts/cpujul2022.html