cbcvebase.

Oracle Http Server vulnerabilities

104 known vulnerabilities affecting oracle/http_server.

Total CVEs
104
CISA KEV
3
actively exploited
Public exploits
11
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH39MEDIUM32LOW6

Vulnerabilities

Page 5 of 6
CVE-2002-0655P4HIGHCVSS 7.5v9.0.1v9.2.02002-08-12
CVE-2002-0655 [HIGH] CVE-2002-0655: OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representati OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.
nvd
CVE-2025-21498P4MEDIUMCVSS 5.3v12.2.1.4.02025-01-21
CVE-2025-21498 [MEDIUM] CWE-862 CVE-2025-21498: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). The Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized read acc
nvd
CVE-2021-35940P4HIGHCVSS 7.1v12.2.1.3.0v12.2.1.4.02021-08-23
CVE-2021-35940 [HIGH] CVE-2021-35940: An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtim An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
nvd
CVE-2007-0279P4HIGHCVSS 7.5v9.2.0.82007-01-17
CVE-2007-0279 [HIGH] CVE-2007-0279: Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and A Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.
nvd
CVE-2024-20991P4MEDIUMCVSS 5.3v12.2.1.4.02024-04-16
CVE-2024-20991 [MEDIUM] CWE-200 CVE-2024-20991: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2020-2530P4MEDIUMCVSS 6.1v11.1.1.9.0v12.1.3.0.0+1 more2020-01-15
CVE-2020-2530 [MEDIUM] CVE-2020-2530: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks require human interaction from
nvd
CVE-2018-2561P4MEDIUMCVSS 5.3v11.1.1.7.0v11.1.1.9.0+3 more2018-01-18
CVE-2018-2561 [MEDIUM] CVE-2018-2561: Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Lis Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of
nvd
CVE-2021-2315P4MEDIUMCVSS 5.4v11.1.1.9.0v12.2.1.3.0+1 more2021-04-22
CVE-2021-2315 [MEDIUM] CVE-2021-2315: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks require human interaction from
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v12.2.1.3.0v12.2.1.4.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2022-21271P4MEDIUMCVSS 5.3v12.2.1.3.0v12.2.1.4.02022-01-19
CVE-2022-21271 [MEDIUM] CVE-2022-21271: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protoc
nvd
CVE-2006-5346P4HIGHCVSS 7.6v9.2.0.72006-10-18
CVE-2006-5346 [HIGH] CVE-2006-5346: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, as used in Oracle Collaboration Suite 9.0.4 Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, as used in Oracle Collaboration Suite 9.0.4.2 and Oracle E-Business Suite and Applications 11.5.10CU2, has unknown impact and remote attack vectors related to htdigest, aka Vuln# OHS02.
nvd
CVE-2020-2545P4MEDIUMCVSS 5.3v11.1.1.9.0v12.1.3.0.0+1 more2020-01-15
CVE-2020-2545 [MEDIUM] CVE-2020-2545: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module) Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can resul
nvd
CVE-2019-0197P4MEDIUMCVSS 4.2v12.2.1.3.02019-06-11
CVE-2019-0197 [MEDIUM] CWE-444 CVE-2019-0197: A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled
nvd
CVE-2007-0281P4MEDIUMCVSS 5.0v9.0.1.52007-01-17
CVE-2007-0281 [MEDIUM] CVE-2007-0281: Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1, and 10.1.3.0; and Collaboration Suite 9.0.4.2 and 10.1.2; have unknown impact and attack vectors related to the Oracle HTTP Server, aka (1) OHS03 and (2) OHS04.
nvd
CVE-2022-21375P4MEDIUMCVSS 5.5v12.2.1.3.0v12.2.1.4.02022-01-19
CVE-2022-21375 [MEDIUM] CVE-2022-21375: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported ver Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2012-2751P4MEDIUMCVSS 4.3v11.1.1.6.02012-07-22
CVE-2012-2751 [MEDIUM] CVE-2012-2751: ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the begi ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks. NOTE:
nvd
CVE-2006-5350P4HIGHCVSS 7.2v9.2.0.72006-10-18
CVE-2006-5350 [HIGH] CVE-2006-5350: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and Oracle E-Business Suite and Applications Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and local attack vectors, aka Vuln# OHS08.
nvd
CVE-2021-4183P4MEDIUMCVSS 5.5v12.2.1.3.0v12.2.1.4.02021-12-30
CVE-2021-4183 [MEDIUM] CWE-125 CVE-2021-4183: Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
nvd
CVE-2016-3482P4LOWCVSS 3.7v11.1.1.9v12.1.3.02016-07-21
CVE-2016-3482 [LOW] CVE-2016-3482: Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.9 a Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.9 and 12.1.3.0 allows remote attackers to affect confidentiality via vectors related to SSL/TLS Module.
nvd
CVE-2016-0671P4LOWCVSS 3.7v12.1.2.02016-04-21
CVE-2016-0671 [LOW] CVE-2016-0671: Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 12.1.2.0 a Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 12.1.2.0 allows remote attackers to affect confidentiality via vectors related to OSSL Module.
nvd