QID 730108

Date Published: 2021-06-14

QID 730108: Apache HTTP Server Denial of Service Vulnerability

Apache HTTP Server is an HTTP web server application.

Affected Versions:
Apache HTTP Server versions prior to 2.4.48.

QID Detection Logic:(Unauthenticated)
This QID checks for server banner to detect if the target is running vulnerable version of apache httpd.

Successful exploitation of this vulnerability may allow an attacker to crash memory and DOS to server.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to update latest Apache httpd 2.4.48.
    For more information, visit here.
    Vendor References

    CVEs related to QID 730108

    Software Advisories
    Advisory ID Software Component Link
    Apache HTTP Server 2.4.48 URL Logo httpd.apache.org/security/vulnerabilities_24.html