IBM Support

IBM HTTP Server is vulnerable to arbitrary code execution due to Expat (CVE-2022-40674 CVSS 9.8)

Download


Downloadable File

File link File size File description

Abstract

IBM HTTP Server is vulnerable to arbitrary code execution due to Expat (CVE-2022-40674 CVSS 9.8)

Download Description

PH49572 resolves the following problem:

ERROR DESCRIPTION:
IBM HTTP Server is vulnerable to arbitrary code execution due to Expat (CVE-2022-40674 CVSS 9.8)

PROBLEM SUMMARY:
IBM HTTP Server is vulnerable to arbitrary code execution due to Expat (CVE-2022-40674 CVSS 9.8)
PROBLEM CONCLUSION:
Confidential for CVE-2022-40674

The fix for this APAR is currently targeted for inclusion in fix packs 8.5.5.23 and 9.0.5.14

For more information, see 'Recommended Updates for WebSphere Application Server':
http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980

This fix is superseded by later interim fixes.

The interim fix for this APAR has been superseded by a later interim fix. Download and install the interim fix for PH50316 to resolve this APAR. 


Mitigations and affected configurations:
 
  • CVE-2022-40674
    • IBM HTTP Server on z/OS is not vulnerable, the expat library is not included in IHS on z/OS.
    • IBM HTTP Server without third-party modules added to the server is not vulnerable.
      • If third-party modules are present, a third-party module that uses the expat library may be vulnerable if it calls expat in the way described by CVE-2022-40674.

Prerequisites

None

Download Package

This fix is superseded by later interim fixes.

The interim fix for this APAR has been superseded by a later interim fix. Download and install the interim fix for PH50316 to resolve this APAR. 

Problems Solved

PH49572

On

Technical Support

Contact IBM Support at https://www.ibm.com/mysupport/ or 1-800-IBM-SERV (US only).

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"ARM Category":[{"code":"a8m0z000000XatiAAC","label":"IBM HTTP Server\/WebSphere Plugin-All Platforms-\u003EIHS-\u003EIHS.Security Vulnerabilities"}],"ARM Case Number":"","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"All Versions"}]

Document Information

Modified date:
14 November 2022

UID

ibm16826609