Fix (APAR): PH21992 Status: Fix Release: 9.0.5.3,9.0.5.2,9.0.5.1 Operating System: AIX,HP-UX,Linux,Solaris,Windows,z/OS Supersedes Fixes: CMVC Defect: xxxxxx Byte size of APAR: 31350305 Date: 2020-04-13 Abstract: Multiple vulnerabilities in IBM HTTP Server (CVE-2020-1927, CVE-2020-1934) Description/symptom of problem: PH21992 resolves the following problem: ERROR DESCRIPTION: CVE-2020-1927: IBM HTTP Server could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in the mod_rewrite module. CVE-2020-1934: IBM HTTP Server could allow a remote attacker to execute arbitrary code on the system, caused by the use of an uninitialized value in mod_proxy_ftp. LOCAL FIX: PROBLEM SUMMARY: CVE-2020-1927, CVE-2020-1934 in IBM HTTP Server. PROBLEM CONCLUSION: IHS was updated to resolve the vulnerabilities. This fix is targeted for IBM HTTP Server fix packs: - 8.5.5.18 - 9.0.5.4 Directions to apply fix: Special Instructions: None NOTE: The user must: * Be at V1.8.5 or newer of the Installation Manager. Certain iFixes may require a newer version of the Installation Manager and the Installation Manager will inform you during the installation process if a newer version is required. * Be logged in with the same authority level when unpacking a fix, fix pack, or refresh pack. The IBM Information Center can provide details, if needed, on the use of the Installation Manager to apply the interim fix: http://www.ibm.com/support/knowledgecenter/SSDV2W_1.8.5/com.ibm.cic.agent.ui.doc/helpindex_imic.html. 1) Shutdown IBM HTTP Server 2) Apply the interim fix using Installation Manager 3) Restart IBM HTTP Server Directions to remove fix: The IBM Information Center can provide details, if needed, on the use of the Installation Manager to remove the interim fix: http://www.ibm.com/support/knowledgecenter/SSDV2W_1.8.5/com.ibm.cic.agent.ui.doc/helpindex_imic.html. 1) Shutdown IBM HTTP Server 2) Remove the interim fix using Installation Manager 3) Restart IBM HTTP Server Directions to re-apply fix: 1) Stop IBM HTTP Server. 2) Follow the directions to apply the fix. 3) Restart IBM HTTP Server. Additional Information: