QID 379266

Date Published: 2024-01-17

QID 379266: Oracle Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (CPUJAN2024)

Oracle HTTP Server is the Web server component for Oracle Fusion Middleware. It provides a listener for Oracle WebLogic Server and the framework for hosting static pages, dynamic pages, and applications over the Web.

Affected Versions:
Oracle HTTP Server, version 12.2.1.4.0

NOTE:
The vendor has not yet released the patch, and its release is scheduled for January 30, 2024. Detection will be updated once the patch becomes available.

QID Detection Logic (Authenticated):
This QID checks the vulnerable version of Oracle HTTP Server from file "inventory.xml" from the Home Directory.

Successful exploitation of this vulnerability may affect Confidentiality, Integrity and Availability.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to vendor advisory Oracle HTTP Server JAN 2024

    CVEs related to QID 379266

    Software Advisories
    Advisory ID Software Component Link
    CPUJAN2024 URL Logo www.oracle.com/security-alerts/cpujan2024.html#AppendixFMW