Fix (APAR): PH49572 Status: Fix Release: 8.0.0.15 Operating System: AIX,HP-UX,Linux,Solaris,Windows,z/OS Supersedes Fixes: PH46897 PH44829 PH44271 PH43122 PH40343 PH35771 PH36939 PH21992 PH14974 PH09869 PH00888 PI95670 PI90598 PI87445 PI87663 CMVC Defect: xxxxxx Byte size of APAR: 71766164 Date: 2022-10-03 Abstract: IBM HTTP Server is vulnerable to arbitrary code execution due to Expat (CVE-2022-40674 CVSS 9.8) Description/symptom of problem: PH49572 resolves the following problem: ERROR DESCRIPTION: Confidential for Security Integrity interim fix CVE-2022-40674 PROBLEM SUMMARY: Confidential for Security Integrity interim fix CVE-2022-40674 PROBLEM CONCLUSION: Confidential for CVE-2022-40674 Directions to apply fix: Special Instructions: None NOTE: The user must: * Be at V1.4.3 or newer of the Installation Manager. Certain iFixes may require a newer version of the Installation Manager and the Installation Manager will inform you during the installation process if a newer version is required. * Be logged in with the same authority level when unpacking a fix, fix pack, or refresh pack. The IBM Knowledge Center can provide details, if needed, on the use of the Installation Manager to apply the interim fix: http://publib.boulder.ibm.com/infocenter/install/v1r4/index.jsp. 1) Shutdown IBM HTTP Server 2) Apply the interim fix using Installation Manager 3) Restart IBM HTTP Server Directions to remove fix: The IBM Knowledge Center can provide details, if needed, on the use of the Installation Manager to remove the interim fix: http://publib.boulder.ibm.com/infocenter/install/v1r4/index.jsp. 1) Shutdown IBM HTTP Server 2) Remove the interim fix using Installation Manager 3) Restart IBM HTTP Server Directions to re-apply fix: 1) Stop IBM HTTP Server. 2) Follow the directions to apply the fix. 3) Restart IBM HTTP Server. Additional Information: