Description
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle HTTP Server accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Remediation
References
Related Vulnerabilities
Envoy Proxy Incorrect Authorization Vulnerability (CVE-2021-32777)
MySQL CVE-2015-4862 Vulnerability (CVE-2015-4862)
WordPress Inadequate Encryption Strength Vulnerability (CVE-2012-6707)
OpenSSL Out-of-bounds Write Vulnerability (CVE-2023-6129)
SharePoint Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-1261)