QID 376041
Date Published: 2021-11-23
QID 376041: IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6493841)
BM HTTP Server powered by Apache is based on the Apache HTTP Server available for multiple platforms.
CVE-2021-34798 - Apache HTTP Server is vulnerable to a denial of service, caused by a NULL pointer dereference in httpd core. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
CVE-2021-40438 - Apache HTTP Server is vulnerable to server-side request forgery, caused by an error in mod_proxy. By sending a specially crafted request uri-path, a remote attacker could exploit this vulnerability to forward the request to an origin server chosen by the remote user.
Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.9
I
QID Detection Logic (Authenticated):
This checks for vulnerable version of IBM HTTP server.
A remote attacker could exploit this vulnerability to obtain sensitive information, escalate privileges or cause a denial of service.
- Security Bulletin 6493841 -
www.ibm.com/support/pages/node/6493841
CVEs related to QID 376041
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| IBM HTTP Server |
|