QID 376838
Date Published: 2023-03-08
QID 376838: IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6191631)
BM HTTP Server powered by Apache is based on the Apache HTTP Server available for multiple platforms.
CVE-2020-1927: Apache HTTP Server could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in the mod_rewrite module.
CVE-2020-1934: Apache HTTP Server could allow a remote attacker to execute arbitrary code on the system, caused by the use of uninitialized value in mod_proxy_ftp. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.3
IBM HTTP Server V8.5.0.0 through 8.5.5.17
IBM HTTP Server V8.0.0.0 through 8.0.0.15
IBM HTTP Server V70.0.0 through 7.0.0.45
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.
QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.
An attacker could exploit this vulnerability using a specially-crafted URL to redirect a victim to arbitrary Web sites.
CVEs related to QID 376838
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6191631 |
|