Oracle recommends customers apply Security Alert fixes as soon as possible. The bug has existed for a long time and was being exploited in at least late summer. It is surprising to see that an Apache bug being publicly exploited and reported on mid-August, patched by the Apache group, receives a delayed patch delivery from Oracle in mid September. Coincidentally, the Weblogic host serving resources at that URL returns an Apache error: Failure of server APACHE bridge: No backend server available”]
Source: https://securelist.com/oracle-out-of-cycle-apache-patch-cve-2011-3192/29552/