QID 376862

Date Published: 2023-03-20

QID 376862: IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (964768)

BM HTTP Server powered by Apache is based on the Apache HTTP Server available for multiple platforms.

CVE-2018-20843:libexpat is vulnerable to a denial of service, caused by an error in the XML parser.
CVE-2019-10092: Apache HTTP Server is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the mod_proxy error page.
CVE-2019-10098: Apache HTTP Server could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in the mod_rewrite module.

Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.0
IBM HTTP Server V8.5.5.0 through 8.5.5.16
IBM HTTP Server V8.0.0.0 through 8.0.0.15
IBM HTTP Server V70.0.0 through 7.0.0.45
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.

QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.

An attacker could exploit this vulnerability using a specially-crafted URL to redirect a victim to arbitrary Web sites.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    The vendor has released advisories and updates to fix these vulnerabilities. Refer to the following link for further details: 964768
    Vendor References

    CVEs related to QID 376862

    Software Advisories
    Advisory ID Software Component Link
    964768 URL Logo www.ibm.com/support/pages/node/964768