Apache 2.0.52 vulnerability : Web Server Expect Header XSS
Hi,
I hope someone can help me out here. We recently had a penetration test run on our network and the following vulnerability was identified
"The remote web server fails to sanitize the contents of an 'Expect' request header before using it to generate dynamic web content. An
unauthenticated, remote attacker may be able to leverage this issue to launch cross-site scripting attacks against the affected service,
perhaps through specially crafted ShockWave (SWF) files."
This can be fixed by upgrading our current version of Apache Webserver 2.0.52 to 2.0.63. We are running Oracle Applications 11.5.10.2. Was there a patch released by Oracle to fix this vulnerability? I don't think I should be upgrading Apache on it's own