Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2024-38472
Published: July 1, 2024 / Updated: August 9, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the web server to leak NTLM hashes.
Note, the vulnerability affects Windows installations only.
Affected software
IBM HTTP Server
IBM Business Automation Workflow
EasyApache
IBM Tivoli Monitoring
IBM Rational Build Forge
EMC NetWorker Server
Gentoo Linux
Slackware Linux
Anolis OS
SecurityCenter
JBoss Core Services
httpd
www-servers/apache
httpd-manual
httpd-filesystem
httpd-doc
mod_ssl
mod_session
mod_proxy_html
mod_lua
mod_ldap
httpd-tools
httpd-devel
httpd-core
Dell EMC OpenManage Enterprise Modular
IBM Aspera Console
NetWorker Management Console (NMC)
How to mitigate CVE-2024-38472
EasyApache - update to 4 2024-7-10
SecurityCenter - update to SC-202408.1
JBoss Core Services - update to 2.4.57 SP6
httpd - update to 2.4.60
www-servers/apache - update to 2.4.62
httpd-manual - update to 2.4.62-1
httpd-filesystem - update to 2.4.62-1
httpd-doc - update to 2.4.62-1
mod_ssl - update to 2.4.62-1
mod_session - update to 2.4.62-1
mod_proxy_html - update to 2.4.62-1
mod_lua - update to 2.4.62-1
mod_ldap - update to 2.4.62-1
httpd-tools - update to 2.4.62-1
httpd-devel - update to 2.4.62-1
httpd-core - update to 2.4.62-1
httpd - update to 2.4.62-1
Dell EMC OpenManage Enterprise Modular - update to 2.20.10
IBM Aspera Console - update to 3.4.5
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Rational Build Forge - update to 8.0.0.27
IBM HTTP Server - addressed in versions 8.5.5.27, 9.0.5.21
EMC NetWorker Server - update to 19.10.0.5
NetWorker Management Console (NMC) - update to 19.10.0.5
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Slackware Linux update for httpd
- Multiple vulnerabilities in Tenable Security Center
- Multiple vulnerabilities in IBM HTTP Server
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Gentoo update for Apache HTTPD
- Multiple vulnerabilities in IBM Aspera Console
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in cPanel EasyApache
- Multiple vulnerabilities in Dell NetWorker And NetWorker Management Console
- Multiple vulnerabilities in Dell OpenManage Enterprise Modular
- Anolis OS update for httpd