SB2024103146 - IBM Datapower Operations Dashboard update for Apache HTTP Server



SB2024103146 - IBM Datapower Operations Dashboard update for Apache HTTP Server

Published: October 31, 2024

Security Bulletin ID SB2024103146
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2024-38476)

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker with control over the backend server can run local handlers via internal redirect and gain access to sensitive information or compromise the affected system.


Remediation

Install update from vendor's website.