Apache.mod_proxy.Reverse.Proxy.Exposure

description-logoDescription

This indicates an attack attempt to exploit a Resource Explosure vulnerability in Apache Server.
The vulnerability is located in the "mod_proxy" module, which does not properly interact with "RewriteRule" and "ProxyPassMatch" pattern matches for configuration of a reverse proxy. It may allow remote attackers to access any intranet resources via a crafted URI.

affected-products-logoAffected Products

Apache HTTP Server 1.3.x through 1.3.42
Apache HTTP Server 2.0.x through 2.0.64
Apache HTTP Server 2.2.x through 2.2.21

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Apply the patch, available from the web site.
http://svn.apache.org/viewvc?view=revision&revision=1179239

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)