Lucene search

K
ibmIBMCB737895765C6DE46DC301F7ACA819C4579072B1980414DB9B34FAC2A23E2B52
HistoryMar 13, 2019 - 8:35 p.m.

Security Bulletin: Security vulnerability in the IBM HTTP Server (CVE-2018-17199)

2019-03-1320:35:01
www.ibm.com
21

EPSS

0.002

Percentile

56.6%

Summary

There is a vulnerability in the IBM HTTP Server used by WebSphere Application Server.

Vulnerability Details

CVEID: CVE-2018-17199 DESCRIPTION: Apache HTTP Server could allow a remote attacker to bypass security restrictions, caused by checking the session expiry time before decoding the session by mod_session. An attacker could exploit this vulnerability to ignore session expiry time and gain access to the application.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/156006&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

This vulnerability affects the following version and release of IBM HTTP Server (powered by Apache) component in all editions of WebSphere Application Server and bundling products.

  • Version 9.0

Remediation/Fixes

For V9.0.0.0 through 9.0.0.10:
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PH06010
--OR–
· Apply Fix Pack 9.0.0.11 or later (targeted availability 2Q 2019).