QID 379506

Date Published: 2024-03-19

QID 379506: IBM Hypertext Transfer Protocol (HTTP) Denial of Service (DOS) Vulnerability (7129933)

BM HTTP Server, which is used by IBM WebSphere Application Server, is vulnerable to a denial of service due to libexpat using a specially crafted request.

Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.18
IBM HTTP Server V8.5.0.0 through 8.5.5.25
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.

QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.

A remote attacker could exploit this vulnerability to cause a denial of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    The vendor has released advisories and updates to fix these vulnerabilities. Refer to the following link for further details: 7129933
    Vendor References

    CVEs related to QID 379506

    Software Advisories
    Advisory ID Software Component Link
    7129933 URL Logo www.ibm.com/support/pages/node/7129933