Impact
A vulnerability in the mod_http2.so component of Oracle HTTP Server allows an attacker with local logon and low privileges to compromise the server. Successful exploitation can lead to full control over the Oracle HTTP Server instance, resulting in confidentiality, integrity, and availability impacts.
Affected Systems
Oracle Corporation’s Oracle HTTP Server version 14.1.2.0.0 is affected. The flaw resides in the mod_http2.so module used by this version of the software.
Risk and Exploitability
The CVSS score of 7.8 and the need for local, low‑privilege access indicate a substantial impact, although the attack surface is limited to the affected host. The EPSS score of less than 1% suggests exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment