7.5
CVSSv3

CVE-2022-26377

Published: 09/06/2022 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an malicious user to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache http server

fedoraproject fedora 35

fedoraproject fedora 36

netapp clustered data ontap -

Vendor Advisories

Debian Bug report logs - #1012513 apache2: CVE-2022-31813 CVE-2022-26377 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30522 CVE-2022-30556 Package: src:apache2; Maintainer for src:apache2 is Debian Apache Maintainers <debian-apache@listsdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, ...
Several security issues were fixed in Apache HTTP Server ...
USN-5487-1 introduced a regression in Apache ...
USN-5487-1 introduced a regression in Apache HTTP Server ...
Synopsis Moderate: httpd:24 security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the httpd:24 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update ...
Synopsis Moderate: httpd security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for httpd is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this ...
Synopsis Moderate: httpd24-httpd security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for httpd24-httpd is now available for Red Hat Software CollectionsRed Hat Product Security has rated ...
Synopsis Moderate: Red Hat JBoss Core Services Apache HTTP Server 2451 SP1 security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat JBoss Core ServicesRed Hat Product Securi ...
Synopsis Important: Red Hat JBoss Core Services Apache HTTP Server 2451 SP1 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Core ServicesRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base sco ...
An HTTP request smuggling vulnerability was found in the mod_proxy_ajp module of httpd This flaw allows an attacker to smuggle requests to the AJP server, where it forwards requests (CVE-2022-26377) An out-of-bounds read vulnerability was found in the mod_isapi module of httpd The issue occurs when httpd is configured to process requests with th ...
An HTTP request smuggling vulnerability was found in the mod_proxy_ajp module of httpd This flaw allows an attacker to smuggle requests to the AJP server, where it forwards requests (CVE-2022-26377) An out-of-bounds read vulnerability was found in the mod_isapi module of httpd The issue occurs when httpd is configured to process requests with th ...
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to This issue affects Apache HTTP Server Apache HTTP Server 24 version 2453 and prior versions ...
An HTTP request smuggling vulnerability was found in the mod_proxy_ajp module of httpd This flaw allows an attacker to smuggle requests to the AJP server, where it forwards requests (CVE-2022-26377) An out-of-bounds read vulnerability was found in the mod_isapi module of httpd The issue occurs when httpd is configured to process requests with th ...
An HTTP request smuggling vulnerability was found in the mod_proxy_ajp module of httpd This flaw allows an attacker to smuggle requests to the AJP server, where it forwards requests (CVE-2022-26377) An out-of-bounds read vulnerability was found in the mod_isapi module of httpd The issue occurs when httpd is configured to process requests with th ...

ICS Advisories

Github Repositories

CVE-2022-26377 A Proof of Concept developed by @watchTowr to exploit an AJP Smuggling vulnerability to poison the HTTP Response Queue of an IBM QRadar instance with a stored redirect Follow the watchTowr Labs Team for our Security Research labswatchtowrcom/ twittercom/watchtowrcyber wwwibmcom/support/pages/node/7145265

Recent Articles

F5 hurriedly squashes BIG-IP remote code execution bug
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Fixes came earlier than scheduled as vulnerability became known to outsiders

F5 has issued a fix for a remote code execution (RCE) bug in its BIG-IP suite carrying a near-maximum severity score. Researchers at Praetorian first discovered the authentication bypass flaw in BIG-IP's configuration utility and published their findings this week of what is the third major RCE bug to impact BIG-IP since 2020. Tracked as CVE-2023-46747, the vulnerability was assigned an initial severity score of 9.8 out of a possible 10 on the CVSS scale and if exploited could lead to total syst...