PT-2019-1203 · Oracle · Oracle Http Server
Published
2019-01-16
·
Updated
2020-08-24
·
CVE-2019-2414
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Oracle HTTP Server version 12.2.1.3
Description
The issue is related to inadequate access control in the Web Listener subcomponent of Oracle HTTP Server, allowing a low-privileged attacker with logon access to the infrastructure to compromise Oracle HTTP Server. Successful exploitation can result in the takeover of Oracle HTTP Server.
Recommendations
For Oracle HTTP Server version 12.2.1.3, update to a version that addresses the inadequate access control issue in the Web Listener subcomponent to prevent potential takeover of Oracle HTTP Server.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Http Server