Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2024-43394
Published: July 10, 2025 / Updated: July 10, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input when handling UNC paths on Windows. A remote attacker can trick the application into initiating requests to arbitrary systems and potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input.
Note, the vulnerability affects Windows installations only.
Affected software
IBM HTTP Server
Gentoo Linux
EasyApache
WebSphere Remote Server
IBM Rational ClearCase
IBM Rational ClearQuest
Oracle HTTP Server
IBM Business Automation Workflow
IBM Tivoli Monitoring
IBM Tivoli Netcool Configuration Manager
DevOps Code ClearCase
www-servers/apache
How to mitigate CVE-2024-43394
EasyApache - update to 4 25-24
IBM HTTP Server - addressed in versions 8.5.5.29, 9.0.5.25
www-servers/apache - update to 2.4.68
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Multiple vulnerabilities in IBM HTTP Server
- cPanel EasyApache4 update for Apache HTTP Server
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Rational ClearQuest
- Multiple vulnerabilities in IBM Tivoli Netcool Configuration Manager
- Multiple vulnerabilities in IBM DevOps Code ClearCase
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Multiple vulnerabilities in Oracle HTTP Server
- Gentoo update for Apache HTTPD