Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
BID:100872
CVE-2017-9798 |Info
Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
| Bugtraq ID: | 100872 |
| Class: | Design Error |
| CVE: |
CVE-2017-9798 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 18 2017 12:00AM |
| Updated: | Jan 16 2019 08:00AM |
| Credit: | Hanno Böck |
| Vulnerable: |
Redhat Software Collections for RHEL 0 Redhat JBoss EWS 2 Redhat Jboss EAP 6 Redhat JBoss Core Services 1 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 Redhat Enterprise Linux 5 Oracle Secure Global Desktop 5.3 Oracle Retail Xstore Point of Service 7.1.6 Oracle Retail Xstore Point of Service 7.0.6 Oracle Retail Xstore Point of Service 6.5.11 Oracle Retail Xstore Point of Service 6.0.11 Oracle PeopleSoft Enterprise PeopleTools 8.56 Oracle PeopleSoft Enterprise PeopleTools 8.55 Oracle Oracle HTTP Server 11.1.1.7.0 Oracle HTTP Server 12.2.1.3.0 Oracle HTTP Server 12.2.1.2.0 Oracle HTTP Server 12.1.3.0.0 Oracle HTTP Server 11.1.1.9.0 Oracle Communications Diameter Signaling Router 7.1 Oracle Communications Diameter Signaling Router 6.0.2 Oracle Communications Diameter Signaling Router 6.0 Oracle Communications Diameter Signaling Router 5.1 Oracle Communications Diameter Signaling Router 4.1.6 Oracle Communications Diameter Signaling Router 4.1 Oracle Communications Diameter Signaling Router 8.0 Oracle Communications Diameter Signaling Router 7.0 Oracle Communications Diameter Signaling Router 5.0 Oracle Communications Diameter Signaling Router 4.0 Oracle Communications Diameter Signaling Router 3.0 Apache Apache 2.4.26 Apache Apache 2.4.25 Apache Apache 2.4.23 Apache Apache 2.4.20 Apache Apache 2.4.19 Apache Apache 2.4.18 Apache Apache 2.4.17 Apache Apache 2.4.16 Apache Apache 2.4.14 Apache Apache 2.4.12 Apache Apache 2.4.11 Apache Apache 2.4.10 Apache Apache 2.4.5 Apache Apache 2.4.4 Apache Apache 2.2.34 Apache Apache 2.2.33 Apache Apache 2.2.26 Apache Apache 2.2.25 Apache Apache 2.2.24 Apache Apache 2.2.23 Apache Apache 2.2.15 Apache Apache 2.2.14 Apache Apache 2.2.13 Apache Apache 2.2.12 Apache Apache 2.2.11 Apache Apache 2.2.10 Apache Apache 2.2.9 Apache Apache 2.2.8 Apache Apache 2.2.6 Apache Apache 2.2.5 Apache Apache 2.2.4 Apache Apache 2.2.3 Apache Apache 2.2.2 Apache Apache 2.2 Apache Apache 2.1.9 Apache Apache 2.1.8 Apache Apache 2.1.7 Apache Apache 2.1.6 Apache Apache 2.1.5 Apache Apache 2.1.4 Apache Apache 2.1.3 Apache Apache 2.1.2 Apache Apache 2.1.1 Apache Apache 2.1 Apache Apache 2.0.63 Apache Apache 2.0.61 Apache Apache 2.0.60 Apache Apache 2.0.59 Apache Apache 2.0.58 Apache Apache 2.0.57 Apache Apache 2.0.56 Apache Apache 2.0.55 Apache Apache 2.0.54 Apache Apache 2.0.53 Apache Apache 2.0.52 Apache Apache 2.0.51 Apache Apache 2.0.50 Apache Apache 2.0.49 Apache Apache 2.0.48 Apache Apache 2.0.47 Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0.32 Apache Apache 2.0.28 Apache Apache 2.0.9 Apache Apache 2.0 Apache Apache 1.4 Apache Apache 1.3.68 Apache Apache 1.3.65 Apache Apache 1.3.42 Apache Apache 1.3.41 Apache Apache 1.3.39 Apache Apache 1.3.38 Apache Apache 1.3.37 Apache Apache 1.3.36 Apache Apache 1.3.34 Apache Apache 1.3.33 Apache Apache 1.3.32 Apache Apache 1.3.31 Apache Apache 1.3.30 Apache Apache 1.3.29 Apache Apache 1.3.28 Apache Apache 1.3.27 Apache Apache 1.3.26 Apache Apache 1.3.25 Apache Apache 1.3.24 Apache Apache 1.3.23 Apache Apache 1.3.22 Apache Apache 1.3.20 Apache Apache 1.3.19 Apache Apache 1.3.18 Apache Apache 1.3.17 Apache Apache 1.3.16 Apache Apache 1.3.15 Apache Apache 1.3.14 Apache Apache 1.3.13 Apache Apache 1.3.12 Apache Apache 1.3.11 Apache Apache 1.3.10 Apache Apache 1.3.9 Apache Apache 1.3.8 Apache Apache 1.3.7 Apache Apache 1.3.6 Apache Apache 1.3.5 Apache Apache 1.3.4 Apache Apache 1.3.3 Apache Apache 1.3.2 Apache Apache 1.3.1 Apache Apache 1.3 Apache Apache 1.2.9 Apache Apache 1.2.6 Apache Apache 1.2.5 Apache Apache 1.2.4 Apache Apache 1.2 Apache Apache 1.1.1 Apache Apache 1.1 Apache Apache 1.0.5 Apache Apache 1.0.3 Apache Apache 1.0.2 Apache Apache 1.0 Apache Apache 0.8.14 Apache Apache 0.8.11 Apache Apache 2.4.9 Apache Apache 2.4.8 Apache Apache 2.4.7 Apache Apache 2.4.6 Apache Apache 2.4.3 Apache Apache 2.4.27 Apache Apache 2.4.24 Apache Apache 2.4.2 Apache Apache 2.4.13 Apache Apache 2.4.1 Apache Apache 2.4.0 Apache Apache 2.2.32 Apache Apache 2.2.29 Apache Apache 2.2.22 Apache Apache 2.2.21 Apache Apache 2.2.20 Apache Apache 2.2.19 Apache Apache 2.2.18 Apache Apache 2.2.17 Apache Apache 2.2.16 Apache Apache 2.2.1 Apache Apache 2.2 Apache Apache 2.0.65 Apache Apache 2.0.64 Apache Apache 1.99 Apache Apache 1.3.35 Apache Apache 1.3 |
| Not Vulnerable: |
Oracle Communications Diameter Signaling Router 8.3 |
Discussion
Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
Apache HTTP Server is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in further attacks.
Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27 are vulnerable.
Apache HTTP Server is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in further attacks.
Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27 are vulnerable.
Exploit / POC
Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache HTTP Server CVE-2017-9798 Information Disclosure Vulnerability
References:
References:
- Apache Homepage (Apache)
- Bug 1490344 CVE-2017-9798 httpd: Use-after-free by limiting unregistered HTTP me (Redhat)
- CVE-2017-9798 (Redhat)
- Oracle Critical Patch Update Advisory - April 2018 (Oracle)
- Oracle Critical Patch Update Advisory - January 2018 (Oracle)
- Oracle Critical Patch Update Advisory - January 2019 (Oracle)
- Oracle Critical Patch Update Advisory - October 2018 (Oracle)
- Revision 1807754 (Apache)