QID 376381

Date Published: 2022-02-21

QID 376381: IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6493845,6493841)

BM HTTP Server powered by Apache is based on the Apache HTTP Server available for multiple platforms.

CVE-2021-39275: Apache HTTP Server is vulnerable to a buffer overflow, caused by improper bounds checking by the ap_escape_quotes() function.
CVE-2021-34798: Apache HTTP Server is vulnerable to a denial of service, caused by a NULL pointer dereference in Httpd core.
CVE-2021-40438: Apache HTTP Server is vulnerable to server-side request forgery, caused by an error in mod_proxy.

Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.9
IBM HTTP Server V8.5.0.0 through 8.5.5.20
IBM HTTP Server V8.0.0.0 through 8.0.0.15
IBM HTTP Server V70.0.0 through 7.0.0.45
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.

QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.

An attacker could exploit this vulnerability to ignore session expiry time and gain access to the application.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released advisories and updates to fix these vulnerabilities. Refer to the following link for further details: 64938456493841

    CVEs related to QID 376381

    Software Advisories
    Advisory ID Software Component Link
    6493841 URL Logo www.ibm.com/support/pages/node/6493841
    6493845 URL Logo www.ibm.com/support/pages/node/6493845