QID 378371

Date Published: 2023-07-10

QID 378371: IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6540288)

IBM HTTP Server powered by Apache is based on the Apache HTTP Server available for multiple platforms.

CVE-2021-44224:Apache HTTP Server is vulnerable to a denial of service or server-side request forgery. By sending a specially crafted URI to httpd configured as a forward proxy, an attacker could exploit this vulnerability to cause a NULL pointer dereference. By sending a specially crafted URI to configurations mixing forward and reverse proxy declarations, an attacker could allow for requests to be directed to a declared Unix Domain Socket endpoint.
CVE-2021-44790: Apache HTTP Server is vulnerable to a buffer overflow, caused by improper bounds checking in the mod_lua multipart parser called from Lua scripts). By sending a specially crafted request, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.10
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.

QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.

An attacker can be able to attack on a computer network that limits, restricts, or stops authorized users from accessing system resources..

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released advisories and updates to fix these vulnerabilities. Refer to the following link for further details: 6540288
    Vendor References

    CVEs related to QID 378371

    Software Advisories
    Advisory ID Software Component Link
    6540288 URL Logo www.ibm.com/support/pages/node/6540288