QID 376862
Date Published: 2023-03-20
QID 376862: IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (964768)
BM HTTP Server powered by Apache is based on the Apache HTTP Server available for multiple platforms.
CVE-2018-20843:libexpat is vulnerable to a denial of service, caused by an error in the XML parser.
CVE-2019-10092: Apache HTTP Server is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the mod_proxy error page.
CVE-2019-10098: Apache HTTP Server could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in the mod_rewrite module.
Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.0
IBM HTTP Server V8.5.5.0 through 8.5.5.16
IBM HTTP Server V8.0.0.0 through 8.0.0.15
IBM HTTP Server V70.0.0 through 7.0.0.45
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.
QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.
An attacker could exploit this vulnerability using a specially-crafted URL to redirect a victim to arbitrary Web sites.
CVEs related to QID 376862
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 964768 |
|