PT-2026-3709 · Oracle · Oracle Http Server+1
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle HTTP Server versions 12.2.1.4.0 through 14.1.2.0.0
Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server versions 12.2.1.4.0 through 14.1.2.0.0
Oracle WebLogic Server Proxy Plug-in for IIS version 12.2.1.4.0
Description
An improper access control issue exists in the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. This flaw allows an unauthenticated remote attacker to compromise the system via specially crafted HTTP requests, potentially leading to unauthenticated Remote Code Execution (RCE). Successful exploitation enables the unauthorized creation, modification, or deletion of critical data, and may grant complete access to all data reachable through the affected components. The issue has been actively exploited in the wild, with reports of automated scanning and attacks by Chinese APT groups against government infrastructure. Technical exploitation involves targeting endpoints such as '/weblogic/', '/wl proxy/', '/bea wls internal/', '/ proxy/', and '/proxy/', specifically utilizing the
ProxyServlet via path traversal sequences (e.g., /weblogic/..;/bea wls internal/ProxyServlet). Attackers may also use base64 encoded shell commands within the WL-Proxy-Client-IP, Proxy-Client-IP, or X-Forwarded-For headers to execute arbitrary OS commands.Recommendations
Apply the Oracle Critical Patch Update from January 2026 for Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0.
Apply the Oracle Critical Patch Update from January 2026 for Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0.
Apply the Oracle Critical Patch Update from January 2026 for Oracle WebLogic Server Proxy Plug-in for IIS version 12.2.1.4.0.
Restrict access to WebLogic administrative consoles and proxy endpoints by using a VPN, bastion host, or firewall allowlists to prevent public internet exposure.
Implement WAF or IDS rules to block HTTP requests containing path traversal sequences targeting the
ProxyServlet or base64 encoded strings in HTTP headers.
Disable the vulnerable proxy plug-ins if patching cannot be performed immediately.Exploit
Fix
RCE
Improper Authentication
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Http Server
Oracle Weblogic Server Proxy Plug-In