CVE-2016-3482: Medium severity oracle http server vulnerability
Published Jul 21, 2016
·Updated
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.9 and 12.1.3.0 allows remote attackers to affect confidentiality via vectors related to SSL/TLS Module.
Affected Software
2 affected components
Oracle HTTP Server=11.1.1.9
Oracle HTTP Server=12.1.3.0
Remediation
Event History
Jul 21, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3482?
CVE-2016-3482 is classified as a medium severity vulnerability affecting the Oracle HTTP Server.
2
How do I fix CVE-2016-3482?
To mitigate CVE-2016-3482, update the Oracle HTTP Server to the latest patched version provided by Oracle.
3
What versions of Oracle HTTP Server are affected by CVE-2016-3482?
CVE-2016-3482 affects Oracle HTTP Server versions 11.1.1.9 and 12.1.3.0.
4
Can CVE-2016-3482 allow a remote attacker to gain access?
Yes, CVE-2016-3482 can potentially allow remote attackers to affect confidentiality through the SSL/TLS module.
5
Is there a workaround for CVE-2016-3482 if I cannot update?
Currently, the best recommendation for CVE-2016-3482 is to apply the available patches, as no specific workarounds have been documented.