Impact
The vulnerability in Oracle HTTP Server allows a local attacker who can log onto the underlying infrastructure to compromise and fully take control of the web server. The weakness grants an attacker the ability to alter data, execute commands, and disrupt services, resulting in high confidentiality, integrity, and availability impacts. This is a permission management flaw identified by CWE-269. The entry lists a CVSS 3.1 a substantial risk level once exploited.
Affected Systems
Oracle Corporation's Oracle HTTP Server, specifically versions 12.2.1.4.0 and 14.1.2.0.0. Upgrades to later releases are required to avoid exploitation.
Risk and Exploitability
The CVSS score indicates serious impact, but the EPSS value of less than 1% shows that the likelihood of automated exploitation is very low. Because the vector is local with low privilege, an attacker must already have access to the host where the server runs, as inferred from the description. The vulnerability is not yet listed in CISA's KEV catalog, suggesting no confirmed public exploitation, yet the potential for local compromise remains significant.
OpenCVE Enrichment