Lucene search

K
ibmIBMF8A4D1D317635CAD3DF085B9E8621D4B447F386D6B5594064252F7B7C0BA5B47
HistorySep 08, 2022 - 12:09 a.m.

Security Bulletin: Potential denial of service may affect IBM HTTP Server on Windows (CVE-2015-1829)

2022-09-0800:09:56
www.ibm.com
17
ibm http server
windows
cve-2015-1829
denial of service
vulnerability
fix
upgrade
apache portable runtime
apr named pipe support
ibm support

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.003 Low

EPSS

Percentile

69.8%

Summary

There is a potential denial of service that may affect IBM HTTP Server on Windows (CVE-2015-1829). To exploit the attack requires local access to the server system.

Vulnerability Details

CVEID: CVE-2015-1829**
DESCRIPTION:** Apache Portable Runtime is vulnerable to a denial of service, caused by an error when using APR named pipe support on Windows. An attacker could exploit this vulnerability to cause a pipe squatting attack from a local process.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/103204 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

Affected Products and Versions

The following IBM HTTP Server for WebSphere Application Server may be affected:

  • Version 8.5 and 8.5.5
  • Version 8
  • Version 7
  • Version 6.1

Remediation/Fixes

For affected IBM HTTP Server for WebSphere Application Server: **
For V8.5.0.0 through 8.5.5.5 Full Profile:**

ยท Upgrade to 8.5.5.5 and then apply Interim Fix PI39833

--ORโ€“
ยท Apply Fix Pack 8.5.5.7 or later.

**
For V8.0 through 8.0.0.10:**
ยท Upgrade to 8.0.0.9 and then apply Interim Fix PI39833

--ORโ€“
ยท Apply Fix Pack 8.0.0.11 or later.

**
For V7.0.0.0 through 7.0.0.37:**
ยท Upgrade to 7.0.0.37 and then apply Interim Fix PI39833

--ORโ€“
ยท Apply Fix Pack 7.0.0.39 or later.

For V6.1.0.0 through 6.1.0.47:
ยท Upgrade to Fix Pack 6.1.0.47 and then apply cumulative interim Fix PI39833

**
For V6.0.0.0 through 6.0.2.43:**
ยท Upgrade to Fix Pack 6.0.2.43 and then apply cumulative interim Fix PI39833 from IBM Support.

If you are using an earlier unsupported release, IBM strongly recommends that you upgrade.

Workarounds and Mitigations

none

Affected configurations

Vulners
Node
ibmhttp_serverMatch8.5.5
OR
ibmhttp_serverMatch8.5
OR
ibmhttp_serverMatch8.0
OR
ibmhttp_serverMatch7.0
OR
ibmhttp_serverMatch6.1

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.003 Low

EPSS

Percentile

69.8%

Related for F8A4D1D317635CAD3DF085B9E8621D4B447F386D6B5594064252F7B7C0BA5B47