QID 377911

Date Published: 2023-01-18

QID 377911: Oracle Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities (CPUJAN2023)

Oracle HTTP Server is the Web server component for Oracle Fusion Middleware. It provides a listener for Oracle WebLogic Server and the framework for hosting static pages, dynamic pages, and applications over the Web.

Affected Versions:
Oracle HTTP Server, version, 12.2.1.4.0

QID Detection Logic (Authenticated):
This QID checks the vulnerable version of Oracle HTTP Server from file "inventory.xml" from the Home Directory.

Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Refer to vendor advisory Oracle HTTP Server JAN 2023
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    CPUJAN2023 URL Logo www.oracle.com/security-alerts/cpujan2023.html