[WID-SEC-2022-0727] Apache HTTP Server: Mehrere Schwachstellen CVSS Base Score 10.0 (kritisch) CVSS Temporal Score 8.7 (hoch) Remoteangriff ja Datum 19.12.2021 Stand UPDATE 01.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Apache ist ein Webserver für verschiedene Plattformen. Produkte UPDATE 20.11.2022 IBM Power Hardware Management Console UPDATE 14.08.2022 Gentoo Linux UPDATE 02.03.2022 Avaya Aura Experience Portal UPDATE 27.01.2022 Avaya Aura Communication Manager Avaya Aura Session Manager Avaya Aura Application Enablement Services Avaya Aura System Manager Avaya Web License Manager UPDATE 25.01.2022 Open Source CentOS UPDATE 19.01.2022 Amazon Linux 2 Oracle Linux UPDATE 17.01.2022 SUSE Linux UPDATE 16.01.2022 Red Hat Enterprise Linux UPDATE 06.01.2022 Ubuntu Linux UPDATE 04.01.2022 Debian Linux 19.12.2021 Apache HTTP Server <2.4.52 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um Informationen offenzulegen, einen Denial of Service zu verursacehn und Code auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple critical vulnerabilities in Apache HTTP Server (CVSS Base Score 10.0) allow a remote, anonymous attacker to disclose information, cause a denial of service, and execute arbitrary code. Affected versions are Apache HTTP Server prior to version 2.4.52. A patch is available, and the article lists numerous updated vendor distributions and products as mitigations.