Improper Privilege Management in Apache HTTP Server - CVE-2020-13938

 

Improper Privilege Management in Apache HTTP Server - CVE-2020-13938

Published: June 3, 2021


Vulnerability identifier: #VU53779
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13938
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to stop the service.

The vulnerability exists due to improper privilege management. A local user can on the Windows system can stop the Apache HTTP server service.


Affected software

Apache HTTP Server
IBM Tivoli Monitoring
EasyApache
IBM Rational Build Forge
Amazon Linux AMI
MELSOFT iQ AppPortal
IBM Security SiteProtector System
Maximo Application Suite - IoT Component

How to mitigate CVE-2020-13938

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.47
MELSOFT iQ AppPortal - update to 1.29F
EasyApache - update to 4 2021-6-2
IBM Rational Build Forge - update to 8.0.0.21
IBM Security SiteProtector System - update to 3.1.1.16
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6

External References

Related Security Bulletins