Rewterz

Rewterz Threat Alert – A flaw in vCard processing could Allow Hackers to Compromise a Windows PC

January 16, 2019
Rewterz

Rewterz Threat Advisory – Oracle Enterprise Manager for Virtualization Multiple Vulnerabilities

January 17, 2019

Rewterz Threat Advisory – CVE-2019-2414 – Oracle HTTP Server “Web Listener” Privilege Escalation Vulnerability

SEVERITY: Medium

 

 

ANALYSIS SUMMARY

 

 

A vulnerability has been reported in Oracle HTTP Server, which can be exploited by malicious, local users to gain escalated privileges. This vulnerability resides in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener). The supported version that is affected is 12.2.1.3. The flaw can easily be exploited by a low privileged attacker, with logon to the infrastructure where Oracle HTTP Server executes, to compromise Oracle HTTP Server which can be taken over if the attack is successful.

 

 

AFFECTED PRODUCTS

 

 

Oracle HTTP Server 12.x

 

 

IMPACT

 

 

Privilege Escalation

 

 

REMEDIATION 

 

 

Apply update.

https://support.oracle.com/rs?type=doc&id=2466391.1

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.