IBM HTTP Server 6.1 <= 6.1.0.47 (FP47) / 7.0 < 7.0.0.39 (FP39) / 8.0 < 8.0.0.12 (FP12) / 8.5 < 8.5.5.7 (FP7) Multiple Vulnerabilities

high Nessus Plugin ID 86018

Synopsis

The remote IBM HTTP Server is affected by multiple vulnerabilities.

Description

The IBM HTTP Server running on the remote host is version 6.1 prior to or equal to 6.1.0.47, 7.0 prior to 7.0.0.39, 8.0 prior to 8.0.0.12, or 8.5 prior to 8.5.5.7. It is, therefore, potentially affected by multiple vulnerabilities :

- An overflow condition exists in the XML_GetBuffer() function in xmlparse.c due to improper validation of user-supplied input when handling compressed XML content. An attacker can exploit this to cause a buffer overflow, resulting in the execution of arbitrary code.
(CVE-2015-1283)

- A denial of service vulnerability exists when processing an ECParameters structure due to an infinite loop that occurs when a specified curve is over a malformed binary polynomial field. A remote attacker can exploit this to perform a denial of service against any system that processes public keys, certificate requests, or certificates. This includes TLS clients and TLS servers with client authentication enabled. (CVE-2015-1788)

- An information disclosure vulnerability exists that allows an unauthenticated, remote attacker to identify the proxy server software by reading the HTTP 'Via' header. (CVE-2015-1932)

- A flaw exists in the chunked transfer coding implementation due to a failure to properly parse chunk headers. A remote attacker can exploit this to conduct HTTP request smuggling attacks. (CVE-2015-3183)

- An unspecified flaw exists that allows an unauthenticated, remote attacker to spoof servlets or disclose sensitive information. (CVE-2015-4938)

- An overflow condition exists in the Administration Server due to improper validation of user-supplied input. An attacker can exploit this, via a specially crafted request, to cause a stack-based buffer overflow, resulting in a denial of service condition or the execution of arbitrary code. (CVE-2015-4947)

Note that :
- CVE-2015-1788 does not affect the 6.1 and 7.0 branches.
- CVE-2015-1932 and CVE-2015-4938 do not affect the 6.1 branch.

Solution

Apply IBM 7.0 Fix Pack 39 (7.0.0.39) / 8.0 Fix Pack 12 (8.0.0.12) / 8.5 Fix Pack 7 (8.5.5.7) or later. Alternatively, apply the Interim Fixes as recommended in the vendor advisory.

In the case of the 6.1 branch, apply IBM 6.1 Fix Pack 47 (6.1.0.47) and then apply Interim Fixes PI39833 and PI45596.

See Also

http://www-01.ibm.com/support/docview.wss?uid=swg21963361

http://www-01.ibm.com/support/docview.wss?uid=swg21965419

http://www-01.ibm.com/support/docview.wss?uid=swg21963362

http://www-01.ibm.com/support/docview.wss?uid=swg21964428

http://www-01.ibm.com/support/docview.wss?uid=swg21963275

Plugin Details

Severity: High

ID: 86018

File Name: websphere_8_5_5_7.nasl

Version: 1.11

Type: remote

Family: Web Servers

Published: 9/18/2015

Updated: 10/20/2023

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.5

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2015-4947

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:ibm:websphere_application_server, cpe:/a:ibm:http_server

Required KB Items: www/WebSphere, Settings/ParanoidReport

Exploit Ease: No known exploits are available

Patch Publication Date: 9/11/2015

Vulnerability Publication Date: 4/10/2015

Reference Information

CVE: CVE-2015-1283, CVE-2015-1788, CVE-2015-1932, CVE-2015-3183, CVE-2015-4938, CVE-2015-4947

BID: 75158, 75963, 75973, 76463, 76466, 76658

IAVB: 2015-B-0115-S