Risk | High |
Patch available | YES |
Number of vulnerabilities | 11 |
CVE-ID | CVE-2020-14155 CVE-2021-23840 CVE-2019-20838 CVE-2021-26691 CVE-2020-13950 CVE-2021-30641 CVE-2020-35452 CVE-2021-23841 CVE-2021-3712 CVE-2019-17567 CVE-2021-26690 |
CWE-ID | CWE-190 CWE-20 CWE-125 CWE-476 CWE-121 CWE-264 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
JBoss Core Services Server applications / Application servers jbcs-httpd24-mod_security (Red Hat package) Operating systems & Components / Operating system package or component jbcs-httpd24-mod_md (Red Hat package) Operating systems & Components / Operating system package or component jbcs-httpd24-mod_http2 (Red Hat package) Operating systems & Components / Operating system package or component jbcs-httpd24-httpd (Red Hat package) Operating systems & Components / Operating system package or component jbcs-httpd24-openssl-pkcs11 (Red Hat package) Operating systems & Components / Operating system package or component jbcs-httpd24-openssl-chil (Red Hat package) Operating systems & Components / Operating system package or component jbcs-httpd24-nghttp2 (Red Hat package) Operating systems & Components / Operating system package or component jbcs-httpd24-curl (Red Hat package) Operating systems & Components / Operating system package or component jbcs-httpd24-apr-util (Red Hat package) Operating systems & Components / Operating system package or component jbcs-httpd24-apr (Red Hat package) Operating systems & Components / Operating system package or component |
Vendor | Red Hat Inc. |
Security Bulletin
This security bulletin contains information about 11 vulnerabilities.
EUVDB-ID: #VU29488
Risk: High
CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-14155
CWE-ID:
CWE-190 - Integer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow. A remote attacker can pass a large number after a (?C substring, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall updates from vendor's website.
JBoss Core Services: 2.4.37 SP8 - 2.4.37 SP9
jbcs-httpd24-mod_security (Red Hat package): 2.9.2-16.GA.jbcs.el7 - 2.9.2-65.GA.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package): 2.0.8-24.jbcs.el7 - 2.0.8-38.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package): 1.15.7-3.jbcs.el7 - 1.15.7-19.jbcs.el7
jbcs-httpd24-httpd (Red Hat package): 2.4.37-33.jbcs.el7 - 2.4.37-76.jbcs.el7
jbcs-httpd24-openssl-pkcs11 (Red Hat package): 0.4.10-7.jbcs.el7 - 0.4.10-20.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package): 1.0.0-3.jbcs.el7 - 1.0.0-5.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package): 1.39.2-1.jbcs.el7 - 1.39.2-37.jbcs.el7
jbcs-httpd24-curl (Red Hat package): 7.64.1-14.jbcs.el7 - 7.77.0-2.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package): 1.6.1-9.jbcs.el7 - 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package): 1.6.3-14.jbcs.el7 - 1.6.3-105.jbcs.el7
CPE2.3http://access.redhat.com/errata/RHSA-2021:4614
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU50745
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-23840
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input during EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate calls. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
JBoss Core Services: 2.4.37 SP8 - 2.4.37 SP9
jbcs-httpd24-mod_security (Red Hat package): 2.9.2-16.GA.jbcs.el7 - 2.9.2-65.GA.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package): 2.0.8-24.jbcs.el7 - 2.0.8-38.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package): 1.15.7-3.jbcs.el7 - 1.15.7-19.jbcs.el7
jbcs-httpd24-httpd (Red Hat package): 2.4.37-33.jbcs.el7 - 2.4.37-76.jbcs.el7
jbcs-httpd24-openssl-pkcs11 (Red Hat package): 0.4.10-7.jbcs.el7 - 0.4.10-20.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package): 1.0.0-3.jbcs.el7 - 1.0.0-5.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package): 1.39.2-1.jbcs.el7 - 1.39.2-37.jbcs.el7
jbcs-httpd24-curl (Red Hat package): 7.64.1-14.jbcs.el7 - 7.77.0-2.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package): 1.6.1-9.jbcs.el7 - 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package): 1.6.3-14.jbcs.el7 - 1.6.3-105.jbcs.el7
CPE2.3http://access.redhat.com/errata/RHSA-2021:4614
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30256
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2019-20838
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and X or R has more than one fixed quantifier, a related issue to CVE-2019-20454.
MitigationInstall updates from vendor's website.
JBoss Core Services: 2.4.37 SP8 - 2.4.37 SP9
jbcs-httpd24-mod_security (Red Hat package): 2.9.2-16.GA.jbcs.el7 - 2.9.2-65.GA.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package): 2.0.8-24.jbcs.el7 - 2.0.8-38.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package): 1.15.7-3.jbcs.el7 - 1.15.7-19.jbcs.el7
jbcs-httpd24-httpd (Red Hat package): 2.4.37-33.jbcs.el7 - 2.4.37-76.jbcs.el7
jbcs-httpd24-openssl-pkcs11 (Red Hat package): 0.4.10-7.jbcs.el7 - 0.4.10-20.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package): 1.0.0-3.jbcs.el7 - 1.0.0-5.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package): 1.39.2-1.jbcs.el7 - 1.39.2-37.jbcs.el7
jbcs-httpd24-curl (Red Hat package): 7.64.1-14.jbcs.el7 - 7.77.0-2.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package): 1.6.1-9.jbcs.el7 - 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package): 1.6.3-14.jbcs.el7 - 1.6.3-105.jbcs.el7
CPE2.3http://access.redhat.com/errata/RHSA-2021:4614
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU53776
Risk: Low
CVSSv3.1: 5.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-26691
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in mod_session. A a malicious backend server or SessionHeader can trigger a denial of service (DoS) condition.
MitigationInstall updates from vendor's website.
JBoss Core Services: 2.4.37 SP8 - 2.4.37 SP9
jbcs-httpd24-mod_security (Red Hat package): 2.9.2-16.GA.jbcs.el7 - 2.9.2-65.GA.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package): 2.0.8-24.jbcs.el7 - 2.0.8-38.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package): 1.15.7-3.jbcs.el7 - 1.15.7-19.jbcs.el7
jbcs-httpd24-httpd (Red Hat package): 2.4.37-33.jbcs.el7 - 2.4.37-76.jbcs.el7
jbcs-httpd24-openssl-pkcs11 (Red Hat package): 0.4.10-7.jbcs.el7 - 0.4.10-20.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package): 1.0.0-3.jbcs.el7 - 1.0.0-5.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package): 1.39.2-1.jbcs.el7 - 1.39.2-37.jbcs.el7
jbcs-httpd24-curl (Red Hat package): 7.64.1-14.jbcs.el7 - 7.77.0-2.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package): 1.6.1-9.jbcs.el7 - 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package): 1.6.3-14.jbcs.el7 - 1.6.3-105.jbcs.el7
CPE2.3http://access.redhat.com/errata/RHSA-2021:4614
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU53778
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-13950
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in mod_proxy_http. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
JBoss Core Services: 2.4.37 SP8 - 2.4.37 SP9
jbcs-httpd24-mod_security (Red Hat package): 2.9.2-16.GA.jbcs.el7 - 2.9.2-65.GA.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package): 2.0.8-24.jbcs.el7 - 2.0.8-38.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package): 1.15.7-3.jbcs.el7 - 1.15.7-19.jbcs.el7
jbcs-httpd24-httpd (Red Hat package): 2.4.37-33.jbcs.el7 - 2.4.37-76.jbcs.el7
jbcs-httpd24-openssl-pkcs11 (Red Hat package): 0.4.10-7.jbcs.el7 - 0.4.10-20.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package): 1.0.0-3.jbcs.el7 - 1.0.0-5.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package): 1.39.2-1.jbcs.el7 - 1.39.2-37.jbcs.el7
jbcs-httpd24-curl (Red Hat package): 7.64.1-14.jbcs.el7 - 7.77.0-2.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package): 1.6.1-9.jbcs.el7 - 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package): 1.6.3-14.jbcs.el7 - 1.6.3-105.jbcs.el7
CPE2.3http://access.redhat.com/errata/RHSA-2021:4614
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU53774
Risk: Medium
CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-30641
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect parsing of Apache configuration files. An unexpected
Install updates from vendor's website.
JBoss Core Services: 2.4.37 SP8 - 2.4.37 SP9
jbcs-httpd24-mod_security (Red Hat package): 2.9.2-16.GA.jbcs.el7 - 2.9.2-65.GA.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package): 2.0.8-24.jbcs.el7 - 2.0.8-38.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package): 1.15.7-3.jbcs.el7 - 1.15.7-19.jbcs.el7
jbcs-httpd24-httpd (Red Hat package): 2.4.37-33.jbcs.el7 - 2.4.37-76.jbcs.el7
jbcs-httpd24-openssl-pkcs11 (Red Hat package): 0.4.10-7.jbcs.el7 - 0.4.10-20.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package): 1.0.0-3.jbcs.el7 - 1.0.0-5.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package): 1.39.2-1.jbcs.el7 - 1.39.2-37.jbcs.el7
jbcs-httpd24-curl (Red Hat package): 7.64.1-14.jbcs.el7 - 7.77.0-2.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package): 1.6.1-9.jbcs.el7 - 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package): 1.6.3-14.jbcs.el7 - 1.6.3-105.jbcs.el7
CPE2.3http://access.redhat.com/errata/RHSA-2021:4614
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU53775
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-35452
CWE-ID:
CWE-121 - Stack-based buffer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing Digest nounces in mod_auth_digest. A remote unauthenticated attacker can send a specially crafted HTTP request, trigger stack overflow by one nul byte and crash the server.
Install updates from vendor's website.
JBoss Core Services: 2.4.37 SP8 - 2.4.37 SP9
jbcs-httpd24-mod_security (Red Hat package): 2.9.2-16.GA.jbcs.el7 - 2.9.2-65.GA.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package): 2.0.8-24.jbcs.el7 - 2.0.8-38.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package): 1.15.7-3.jbcs.el7 - 1.15.7-19.jbcs.el7
jbcs-httpd24-httpd (Red Hat package): 2.4.37-33.jbcs.el7 - 2.4.37-76.jbcs.el7
jbcs-httpd24-openssl-pkcs11 (Red Hat package): 0.4.10-7.jbcs.el7 - 0.4.10-20.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package): 1.0.0-3.jbcs.el7 - 1.0.0-5.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package): 1.39.2-1.jbcs.el7 - 1.39.2-37.jbcs.el7
jbcs-httpd24-curl (Red Hat package): 7.64.1-14.jbcs.el7 - 7.77.0-2.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package): 1.6.1-9.jbcs.el7 - 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package): 1.6.3-14.jbcs.el7 - 1.6.3-105.jbcs.el7
CPE2.3http://access.redhat.com/errata/RHSA-2021:4614
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU50740
Risk: Medium
CVSSv3.1: 5.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-23841
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the X509_issuer_and_serial_hash() function when parsing the issuer field in the X509 certificate. A remote attacker can supply a specially crafted certificate, trigger a NULL pointer dereference error and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
JBoss Core Services: 2.4.37 SP8 - 2.4.37 SP9
jbcs-httpd24-mod_security (Red Hat package): 2.9.2-16.GA.jbcs.el7 - 2.9.2-65.GA.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package): 2.0.8-24.jbcs.el7 - 2.0.8-38.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package): 1.15.7-3.jbcs.el7 - 1.15.7-19.jbcs.el7
jbcs-httpd24-httpd (Red Hat package): 2.4.37-33.jbcs.el7 - 2.4.37-76.jbcs.el7
jbcs-httpd24-openssl-pkcs11 (Red Hat package): 0.4.10-7.jbcs.el7 - 0.4.10-20.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package): 1.0.0-3.jbcs.el7 - 1.0.0-5.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package): 1.39.2-1.jbcs.el7 - 1.39.2-37.jbcs.el7
jbcs-httpd24-curl (Red Hat package): 7.64.1-14.jbcs.el7 - 7.77.0-2.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package): 1.6.1-9.jbcs.el7 - 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package): 1.6.3-14.jbcs.el7 - 1.6.3-105.jbcs.el7
CPE2.3http://access.redhat.com/errata/RHSA-2021:4614
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU56064
Risk: Medium
CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-3712
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when processing ASN.1 strings related to a confusion with NULL termination of strings in array. A remote attacker can pass specially crafted data to the application to trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.
Install updates from vendor's website.
JBoss Core Services: 2.4.37 SP8 - 2.4.37 SP9
jbcs-httpd24-mod_security (Red Hat package): 2.9.2-16.GA.jbcs.el7 - 2.9.2-65.GA.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package): 2.0.8-24.jbcs.el7 - 2.0.8-38.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package): 1.15.7-3.jbcs.el7 - 1.15.7-19.jbcs.el7
jbcs-httpd24-httpd (Red Hat package): 2.4.37-33.jbcs.el7 - 2.4.37-76.jbcs.el7
jbcs-httpd24-openssl-pkcs11 (Red Hat package): 0.4.10-7.jbcs.el7 - 0.4.10-20.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package): 1.0.0-3.jbcs.el7 - 1.0.0-5.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package): 1.39.2-1.jbcs.el7 - 1.39.2-37.jbcs.el7
jbcs-httpd24-curl (Red Hat package): 7.64.1-14.jbcs.el7 - 7.77.0-2.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package): 1.6.1-9.jbcs.el7 - 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package): 1.6.3-14.jbcs.el7 - 1.6.3-105.jbcs.el7
CPE2.3http://access.redhat.com/errata/RHSA-2021:4614
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU53780
Risk: Medium
CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2019-17567
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to unspecified error within the mod_proxy_wstunnel and mod_proxy_http modules. If mod_proxy_wstunnel is configured on an URL that is not necessarily Upgraded by the origin server and is tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.
MitigationInstall updates from vendor's website.
JBoss Core Services: 2.4.37 SP8 - 2.4.37 SP9
jbcs-httpd24-mod_security (Red Hat package): 2.9.2-16.GA.jbcs.el7 - 2.9.2-65.GA.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package): 2.0.8-24.jbcs.el7 - 2.0.8-38.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package): 1.15.7-3.jbcs.el7 - 1.15.7-19.jbcs.el7
jbcs-httpd24-httpd (Red Hat package): 2.4.37-33.jbcs.el7 - 2.4.37-76.jbcs.el7
jbcs-httpd24-openssl-pkcs11 (Red Hat package): 0.4.10-7.jbcs.el7 - 0.4.10-20.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package): 1.0.0-3.jbcs.el7 - 1.0.0-5.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package): 1.39.2-1.jbcs.el7 - 1.39.2-37.jbcs.el7
jbcs-httpd24-curl (Red Hat package): 7.64.1-14.jbcs.el7 - 7.77.0-2.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package): 1.6.1-9.jbcs.el7 - 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package): 1.6.3-14.jbcs.el7 - 1.6.3-105.jbcs.el7
CPE2.3http://access.redhat.com/errata/RHSA-2021:4614
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU53777
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2021-26690
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in mod_session. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
JBoss Core Services: 2.4.37 SP8 - 2.4.37 SP9
jbcs-httpd24-mod_security (Red Hat package): 2.9.2-16.GA.jbcs.el7 - 2.9.2-65.GA.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package): 2.0.8-24.jbcs.el7 - 2.0.8-38.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package): 1.15.7-3.jbcs.el7 - 1.15.7-19.jbcs.el7
jbcs-httpd24-httpd (Red Hat package): 2.4.37-33.jbcs.el7 - 2.4.37-76.jbcs.el7
jbcs-httpd24-openssl-pkcs11 (Red Hat package): 0.4.10-7.jbcs.el7 - 0.4.10-20.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package): 1.0.0-3.jbcs.el7 - 1.0.0-5.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package): 1.39.2-1.jbcs.el7 - 1.39.2-37.jbcs.el7
jbcs-httpd24-curl (Red Hat package): 7.64.1-14.jbcs.el7 - 7.77.0-2.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package): 1.6.1-9.jbcs.el7 - 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package): 1.6.3-14.jbcs.el7 - 1.6.3-105.jbcs.el7
CPE2.3http://access.redhat.com/errata/RHSA-2021:4614
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.