IBM Security Bulletin: Multiple vulnerabilities in the IBM HTTP Server (CVE-2017-15710, CVE-2017-15715, CVE-2018-1301)

There are multiple vulnerabilities in the IBM HTTP Server used by WebSphere Application Server.

CVE(s): CVE-2018-1301, CVE-2017-15715, CVE-2017-15710

Affected product(s) and affected version(s):

These vulnerabilities affect the following versions and releases of IBM HTTP Server (powered by Apache) component in all editions of WebSphere Application Server and bundling products.

  • Version 9.0
  • Version 8.5
  • Version 8.0
  • Version 7.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg22015344
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/140852
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/140857
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/140858

The post IBM Security Bulletin: Multiple vulnerabilities in the IBM HTTP Server (CVE-2017-15710, CVE-2017-15715, CVE-2018-1301) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2HhU8jb