QID 87486
Date Published: 2022-03-21
QID 87486: IBM Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities (6559296)
Multiple vulnerabilities in the Expat library are affecting the IBM HTTP Server used by IBM WebSphere Application Server.
CVE-2021-45960, CVE-2022-22822, CVE-2022-23990, CVE-2022-22823, CVE-2022-23852, CVE-2022-22825, CVE-2021-46143, CVE-2022-22824, CVE-2022-22826, and CVE-2022-22827
Affected versions:
V9.0.0.0 through 9.0.5.10
V8.5.0.0 through 8.5.5.21
V8.0.0.0 through 8.0.0.15
V7.0.0.0 through 7.0.0.45
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks the key "HKLM\SYSTEM\CurrentControlSet\Services" to see if IBM HTTP vulnerable version installed on the host or not.
QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.
Expat (aka libexpat) could allow a remote attacker to execute arbitrary code on the system in multiple ways, caused by an integer overflow in several different functions. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
- 6559296 -
www.ibm.com/support/pages/node/6559296
CVEs related to QID 87486
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6559296 |
|