QID 87486

Date Published: 2022-03-21

QID 87486: IBM Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities (6559296)

Multiple vulnerabilities in the Expat library are affecting the IBM HTTP Server used by IBM WebSphere Application Server.
CVE-2021-45960, CVE-2022-22822, CVE-2022-23990, CVE-2022-22823, CVE-2022-23852, CVE-2022-22825, CVE-2021-46143, CVE-2022-22824, CVE-2022-22826, and CVE-2022-22827

Affected versions:
V9.0.0.0 through 9.0.5.10
V8.5.0.0 through 8.5.5.21
V8.0.0.0 through 8.0.0.15
V7.0.0.0 through 7.0.0.45
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.

QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.

Expat (aka libexpat) could allow a remote attacker to execute arbitrary code on the system in multiple ways, caused by an integer overflow in several different functions. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    The vendor has released advisories and updates to fix these vulnerabilities. Refer to the following link for further details: 6557294
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    6559296 URL Logo www.ibm.com/support/pages/node/6557294