Impact
The vulnerability resides in the mod_proxy component of Oracle HTTP Server, allowing an unauthenticated attacker to send HTTP requests that bypass normal access controls. The flaw is an access‑control weakness (CWE‑200), enabling the unauthorized disclosure of data served by the server. Successful exploitation can lead to unauthorized access to critical data or full visibility into all accessible data, as reflected by the CVSS 3.1 score of 8.6 and a high impact on confidentiality.
Affected Systems
Oracle HTTP Server versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. Administrators should confirm the presence of the mod_proxy module and ensure these versions are not exposed to untrusted networks.
Risk and Exploitability
The EPSS score is below 1%, suggesting a low likelihood of exploitation at the present moment, yet the absence of authentication and the high CVSS score keep the risk high. The vulnerability is not listed in CISA's KEV catalog, but the scope change indicates other dependent products could also suffer. Likely attack vectors involve direct HTTP requests to the exposed server, bypassing authentication to manipulate proxy forwarding and extract confidential data.
OpenCVE Enrichment