QID 378532
Date Published: 2023-06-28
QID 378532: IBM Hypertext Transfer Protocol (HTTP) Server Information Disclosure Vulnerability (6998037)
IBM HTTP Server used by IBM WebSphere Application Server is vulnerable to information disclosure due to IBM GSKit which is used for SSL connections. This has been addressed in the remediation section.
Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.15
IBM HTTP Server V8.5.0.0 through 8.5.5.23
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.
QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.
A remote attacker could exploit this vulnerability to obtain sensitive information
- 6998037 -
www.ibm.com/support/pages/node/6998037
CVEs related to QID 378532
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6998037 |
|