QID 87470

QID 87470: IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6493841)

BM HTTP Server powered by Apache is based on the Apache HTTP Server available for multiple platforms.

CVE-2021-34798 - Apache HTTP Server is vulnerable to a denial of service, caused by a NULL pointer dereference in httpd core. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
CVE-2021-40438 - Apache HTTP Server is vulnerable to server-side request forgery, caused by an error in mod_proxy. By sending a specially crafted request uri-path, a remote attacker could exploit this vulnerability to forward the request to an origin server chosen by the remote user.

Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.9
I QID Detection Logic (Un-Authenticated):
This checks for vulnerable version of IBM HTTP server.

A remote attacker could exploit this vulnerability to obtain sensitive information, escalate privileges or cause a denial of service.

  • CVSS V3 rated as Critical - 9 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    The vendor has released advisories and updates to fix these vulnerabilities. Refer to the following link for further details: 6493841
    Vendor References

    CVEs related to QID 87470

    Software Advisories
    Advisory ID Software Component Link
    IBM HTTP Server URL Logo www.ibm.com/support/pages/node/6493841