QID 87497
QID 87497: IBM HTTP Server Multiple Expat Vulnerabilities
IBM HTTP Server powered by Apache is based on the Apache HTTP Server available for multiple platforms.
CVE-2022-23990 - Expat (aka libexpat) could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in the doProlog function. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system..
CVE-2022-23852 - Expat (aka libexpat) could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in the XML_GetBuffer function. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system..
7.0,8.0,8.5, and 9.0.
Affected Versions:
IBM HTTP Server V9.0.0.0 through 9.0.5.7
IBM HTTP Server V8.5.0.0 through 8.5.5.19
IBM HTTP Server V8.0.0.0 through 8.0.0.15
IBM HTTP Server V7.0.0.0 through 7.0.0.45
QID Detection Logic (Authenticated):
Operating System: Linux
The QID checks the vulnerable version IBM HTTP Server. "version.signature" is used to verify the version.
Expat (aka libexpat) could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in the doProlog function. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVEs related to QID 87497
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6557294 |
|