IBM Security Bulletin: Security Vulnerabilities in IBM HTTP Server (CVE-2017-9798, CVE-2017-12618)

There is an information disclosure vulnerability and a denial of service vulnerability that affect the IBM HTTP Server used by WebSphere Application Server.

CVE(s): CVE-2017-9798, CVE-2017-12618

Affected product(s) and affected version(s):

These vulnerabilities affect the following versions and releases of IBM HTTP Server (powered by Apache) component in all editions of WebSphere Application Server and bundling products.

  • Version 9.0
  • Version 8.5
  • Version 8.0
  • Version 7.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2jNLVco
X-Force Database: http://ift.tt/2gzpcwg
X-Force Database: http://ift.tt/2jNLYVC

The post IBM Security Bulletin: Security Vulnerabilities in IBM HTTP Server (CVE-2017-9798, CVE-2017-12618) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2hSAvDT