Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2024-40898
Published: July 17, 2024 / Updated: November 15, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input in Apache HTTP Server on Windows with mod_rewrite in server/vhost context. A remote attacker can force the web server to leak NTML hashes to a malicious server via SSRF and malicious requests.
Affected software
IBM HTTP Server
Gentoo Linux
Slackware Linux
Anolis OS
Communications Unified Assurance
IBM Rational ClearQuest
Oracle Communications Cloud Native Core Automated Test Suite
IBM Tivoli Monitoring
IBM Rational Build Forge
EMC NetWorker Server
SecurityCenter
JBoss Core Services
www-servers/apache
httpd
httpd-doc
mod_ssl
mod_session
mod_proxy_html
mod_lua
mod_ldap
httpd-tools
httpd-devel
httpd-core
httpd-filesystem
httpd-manual
IBM Aspera Console
Maximo Application Suite - IoT Component
CTPView
NetWorker Management Console (NMC)
How to mitigate CVE-2024-40898
Communications Unified Assurance - update to 6.0.5
IBM HTTP Server - addressed in versions 8.5.5.27, 9.0.5.21
SecurityCenter - update to SC-202408.1
JBoss Core Services - update to 2.4.57 SP6
www-servers/apache - update to 2.4.62
httpd - update to 2.4.62
httpd-doc - update to 2.4.62-1
mod_ssl - update to 2.4.62-1
mod_session - update to 2.4.62-1
mod_proxy_html - update to 2.4.62-1
mod_lua - update to 2.4.62-1
mod_ldap - update to 2.4.62-1
httpd-tools - update to 2.4.62-1
httpd-devel - update to 2.4.62-1
httpd-core - update to 2.4.62-1
httpd - update to 2.4.62-1
httpd-filesystem - update to 2.4.62-1
httpd-manual - update to 2.4.62-1
IBM Aspera Console - update to 3.4.5
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Rational Build Forge - update to 8.0.0.27
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
CTPView - update to 9.2R1
EMC NetWorker Server - update to 19.10.0.5
NetWorker Management Console (NMC) - update to 19.10.0.5
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Slackware Linux update for httpd
- Multiple vulnerabilities in Tenable Security Center
- Multiple vulnerabilities in IBM HTTP Server
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Gentoo update for Apache HTTPD
- Multiple vulnerabilities in IBM Aspera Console
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Automated Test Suite
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in IBM Rational ClearQuest
- Multiple vulnerabilities in Dell NetWorker And NetWorker Management Console
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Anolis OS update for httpd
- Juniper Networks CTP View update for third-party components