Can we update Apache in EVM Version 4 to a later version?
Issue
-
Our security personnel has reported that scanning software has tagged our EVM appliances for vulnerabilities due to the Apache version being run. (Details below)
-
Can we update Apache in appliances to v2.2.15 or higher without risk. Can Redhat help with a plan to do so to comply with security standards?
-
According to its banner, the version of Apache 2.2 installed on the remote host is older than 2.2.15. Such versions are potentially affected by multiple vulnerabilities :
-
A TLS renegotiation prefix injection attack is possible. CVE-2009-3555
-
The 'mod_proxy_ajp' module returns the wrong status code if it encounters an error which causes the back-end server to be put into an error state. CVE-2010-0408
-
A flaw in the core sub-request process code can lead to sensitive information from a request being handled by the wrong thread if a multi-threaded environment is used. CVE-2010-0434
-
Added 'mod_reqtimeout' module to mitigate Slowloris attacks. CVE-2007-6750
-
Environment
- Enterprise Virtualization Manager Version 4 (EVM)
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.