QID 379384

Date Published: 2024-02-27

QID 379384: IBM Hypertext Transfer Protocol Server (HTTP Server) Vulnerability (7060076)

IBM HTTP Server is vulnerable to information disclosure due to the included Apache HTTP Server (CVE-2023-31122)

Affected versions:
V9.0.0.0 through 9.0.5.17
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.

QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.

A remote attacker could exploit this vulnerability to obtain sensitive information

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    A remote attacker could exploit this vulnerability to obtain sensitive information

    Vendor References

    CVEs related to QID 379384

    Software Advisories
    Advisory ID Software Component Link
    7060076 URL Logo www.ibm.com/support/pages/node/7060076