QID 378677

Date Published: 2023-07-19

QID 378677: Oracle Hypertext Transfer Protocol Server (HTTP Server) Server Multiple Vulnerabilities (CPUJUL2023)

Oracle HTTP Server is the Web server component for Oracle Fusion Middleware. It provides a listener for Oracle WebLogic Server and the framework for hosting static pages, dynamic pages, and applications over the Web.

Affected Versions:
Oracle HTTP Server, versions 12.2.1.4.0

QID Detection Logic (Authenticated):
This QID checks the vulnerable version of Oracle HTTP Server from file "inventory.xml" from the Home Directory.

Successful exploitation could compromise confidentiality, integrity and availability

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Refer to vendor advisory Oracle HTTP Server JUL 2023
    Vendor References

    CVEs related to QID 378677

    Software Advisories
    Advisory ID Software Component Link
    cpujul2023 URL Logo www.oracle.com/security-alerts/cpujul2023.html