QID 330135

Date Published: 2023-04-26

QID 330135: IBM Advanced Interactive eXecutive (AIX) Secure Sockets Layer (SSL) server spoof due to Apache Commons HttpClient (commonshttp_advisory)

A vulnerability in Apache Commons HttpClient could allow a remote attacker to conduct spoofing attacks

Affected Platform:
AIX 7.1, 7.2, 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command lslpp -L | grep -i bos.ecc_client.rte. It also checks for interim fixes installed The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.

Successful exploit allow a remote attacker to conduct spoofing attacks

  • CVSS V3 rated as Medium - 5.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    The vendor has released fixes to commonshttp_advisory this vulnerability.

    CVEs related to QID 330135

    Software Advisories
    Advisory ID Software Component Link
    commonshttp_advisory URL Logo aix.software.ibm.com/aix/efixes/security/commonshttp_advisory.asc