QID 87497

QID 87497: IBM HTTP Server Multiple Expat Vulnerabilities

IBM HTTP Server powered by Apache is based on the Apache HTTP Server available for multiple platforms.

CVE-2022-23990 - Expat (aka libexpat) could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in the doProlog function. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system..
CVE-2022-23852 - Expat (aka libexpat) could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in the XML_GetBuffer function. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system..

7.0,8.0,8.5, and 9.0. Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.7
IBM HTTP Server V8.5.0.0 through 8.5.5.19
IBM HTTP Server V8.0.0.0 through 8.0.0.15
IBM HTTP Server V7.0.0.0 through 7.0.0.45

QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.

Expat (aka libexpat) could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in the doProlog function. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released advisories and updates to fix these vulnerabilities. Refer to the following link for further details: 6557294

    CVEs related to QID 87497

    Software Advisories
    Advisory ID Software Component Link
    6557294 URL Logo www.ibm.com/support/pages/node/6557294