Improper Privilege Management in Apache HTTP Server - CVE-2020-13938
Published: June 3, 2021
Vulnerability identifier: #VU53779
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13938
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to stop the service.
The vulnerability exists due to improper privilege management. A local user can on the Windows system can stop the Apache HTTP server service.
Affected software
Apache HTTP Server
IBM Tivoli Monitoring
EasyApache
IBM Rational Build Forge
Amazon Linux AMI
MELSOFT iQ AppPortal
IBM Security SiteProtector System
Maximo Application Suite - IoT Component
IBM Tivoli Monitoring
EasyApache
IBM Rational Build Forge
Amazon Linux AMI
MELSOFT iQ AppPortal
IBM Security SiteProtector System
Maximo Application Suite - IoT Component
How to mitigate CVE-2020-13938
Install updates from vendor's website.
Apache HTTP Server - update to 2.4.47
MELSOFT iQ AppPortal - update to 1.29F
EasyApache - update to 4 2021-6-2
IBM Rational Build Forge - update to 8.0.0.21
IBM Security SiteProtector System - update to 3.1.1.16
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
MELSOFT iQ AppPortal - update to 1.29F
EasyApache - update to 4 2021-6-2
IBM Rational Build Forge - update to 8.0.0.21
IBM Security SiteProtector System - update to 3.1.1.16
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- cPanel update for EasyApache
- Amazon Linux AMI update for httpd24
- Multiple vulnerabilities in Mitsubishi Electric MELSOFT iQ AppPortal
- Multiple vulnerabilities in IBM Security SiteProtector System
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Multiple vulnerabilities in IBM Rational Build Forge