Impact
Oracle HTTP Server's mod_ssl component contains a broken access control flaw (CWE‑284) that permits an unauthenticated attacker with network access over HTTP to create, delete, or modify any data exposed by the server. This vulnerability allows full control over all critical data, undermining the confidentiality and integrity of the information served via the HTTP interface.
Affected Systems
The flaw affects Oracle Corporation's Oracle HTTP Server in the Fusion Middleware stack. Specifically, all installations of version 12.2.1.4.0 and 14.1.2.0.0 are vulnerable and must be remediated.
Risk and Exploitability
The CVSS v3.1 base score of 9.1 denotes a severe threat. Although the EPSS score is less than 1% and the vulnerability is not currently listed in the CISA KEV catalog, the remote nature and lack of authentication requirements mean that an attacker with network reach to the server can exploit the flaw with minimal effort. Organizations should treat exposure to untrusted networks as a high risk.
OpenCVE Enrichment