QID 378362
Date Published: 2023-04-10
QID 378362: IBM Hypertext Transfer Protocol (HTTP) Server Denial of Service (DoS) Vulnerabilty (6958522)
IBM HTTP Server, which is used by IBM WebSphere Application Server, is vulnerable to a denial of service using a specially crafted URL. This has been addressed in the remediation section below.
Affected Versions:
IBM HTTP Server V8.5.5.22 through 8.5.5.23
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.
QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.
A remote attacker could exploit this vulnerability to cause a denial of service using a specially crafted URL.
Solution
The vendor has released advisories and updates to fix these vulnerabilities. Refer to the following link for further details:
6958522
Vendor References
- 6958522 -
www.ibm.com/support/pages/node/6958522
CVEs related to QID 378362
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6958522 |
|