Impact
This vulnerability resides in the Apache Plugin component of Oracle HTTP Server. An unauthenticated attacker with network access can exploit the identified flaw via an HTTP request. The flaw ultimately allows the attacker to take full control of the server, causing a complete compromise of confidentiality, integrity, and availability. The CVSS 3.1 base score of 9.8 reflects this high‑risk outcome.
Affected Systems
The affected systems are Oracle's Oracle HTTP Server, versions 12.2.1.4.0 and 14.1.2.0.0. These versions are distributed as part of Oracle Fusion Middleware. No other product versions have been confirmed to be vulnerable.
Risk and Exploitability
Attackers can reach the vulnerability over any network that exposes the HTTP service. The vector is network, access required is none, and the attack can be performed remotely without authentication. The EPSS score of less than 1% suggests that exploit activity has not been observed at scale, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the combination of a CVSS score of 9.8 and the ability to fully compromise the server means that the risk remains significant if the vulnerability is not addressed promptly.
OpenCVE Enrichment