QID 377882
Date Published: 2023-01-12
QID 377882: IBM Hypertext Transfer Protocol Server (HTTP Server) Remote Code Execution (RCE) Vulnerability (6827119)
IBM HTTP Server powered by Apache is based on the Apache HTTP Server available for multiple platforms.
CVE-2022-40674: libexpat could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in the doContent function in xmlparse.c.
Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.13
IBM HTTP Server V8.5.0.0 through 8.5.5.22
IBM HTTP Server V8.0.0.0 through 8.0.0.15
IBM HTTP Server V7.0.0.0 through 7.0.0.45
QID Detection Logic (Authenticated):
Linux: Checks for vulnerable version of IBM HTTP Server using the following command "".
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the target system.
Solution
The vendor has released advisories and updates to fix these vulnerabilities. Refer to the following link for further details:
HTTP Server Advisory (6827119)
Vendor References
- 6827119 -
www.ibm.com/support/pages/node/6827119
CVEs related to QID 377882
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6827119 |
|