QID 378328
Date Published: 2023-04-10
QID 378328: IBM Hypertext Transfer Protocol (HTTP) Server Bypass Access Control Vulnerabilty (6963650)
Apache HTTP Server is vulnerable to HTTP request splitting attacks, caused by an error when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch.
Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.15
IBM HTTP Server V8.5.0.0 through 8.5.5.23
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.
QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.
A remote attacker could exploit this vulnerability to bypass access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning.
- 6963650 -
www.ibm.com/support/pages/node/6963650
CVEs related to QID 378328
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6963650 |
|