« Back to list

CVE-2021-40438

Status: AnalyzedCritical (9)⚠ Active exploitation

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

CISA KEV — actively exploited

Affected technologies (39)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2021-40438",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2021-40438",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2021-10-14T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache HTTP Server",
          "versions": [
            {
              "status": "affected",
              "version": "Apache HTTP Server 2.4",
              "versionType": "custom",
              "lessThanOrEqual": "2.4.48"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-09-16T15:15:07.633",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/",
      "tags": [
        "Release Notes"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/",
      "tags": [
        "Release Notes"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://security.gentoo.org/glsa/202208-20",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20211008-0004/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://www.debian.org/security/2021/dsa-4982",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpujan2022.html",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://www.tenable.com/security/tns-2021-17",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://httpd.apache.org/security/vulnerabilities_24.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/202208-20",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20211008-0004/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.debian.org/security/2021/dsa-4982",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpujan2022.html",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tenable.com/security/tns-2021-17",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40438",
      "tags": [
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier."
    },
    {
      "lang": "es",
      "value": "Un uri-path diseñado puede causar que mod_proxy reenvíe la petición a un servidor de origen elegido por el usuario remoto. Este problema afecta a Apache HTTP Server versiones 2.4.48 y anteriores"
    }
  ],
  "lastModified": "2026-08-06T05:16:35.670",
  "cisaActionDue": "2021-12-15",
  "cisaExploitAdd": "2021-12-01",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:resf:rocky_linux:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55B10764-9920-49E3-B816-FCA37E546DF4"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4CFF558-3C47-480D-A2F0-BABF26042943"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92BC9265-6959-4D37-BE5E-8C45E98992F8"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "831F0F47-3565-4763-B16F-C87B1FF2035E"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E3F09B5-569F-4C58-9FCA-3C0953D107B5"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C3741B8-851F-475D-B428-523F4F722350"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62C31522-0A17-4025-B269-855C7F4B45C2"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_arm_64:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F797F2E-00E6-4D03-A94E-524227529A0A"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EFBEEE7-8BC5-4F4E-8EFA-42A6743152BB"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83981111-E13A-4A88-80FD-F63D7CCAA47F"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0_s390x:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2148300C-ECBD-4ED5-A164-79629859DD43"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87C21FE1-EA5C-498F-9C6C-D05F91A88217"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "280D547B-F204-4848-9262-A103176B740C"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C9BD9AE-46FC-4609-8D99-A3CFE91D58D1"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83364F5C-57F4-4D57-B54F-540CAC1D7753"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus_s390x:8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "725566B6-4319-489E-9A69-9E36ED2950DF"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CDCFF34-6F1D-45A1-BE37-6A0E17B04801"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4A684C7-88FD-43C4-9BDB-AE337FCBD0AB"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47811209-5CE5-4375-8391-B0A7F6A0E420"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EB6F417-25D0-4A28-B7BA-D21929EAA9E9"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5C80DB2-4A78-4EC9-B2A8-1E4D902C4834"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "983533DD-3970-4A37-9A9C-582BD48AA1E5"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "729C515E-1DD3-466D-A50B-AFE058FFC94A"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A49ABD84-6755-4894-AD4E-49AAD39933C2"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37CE1DC7-72C5-483C-8921-0B462C8284D1"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51EF4996-72F4-4FA4-814F-F5991E7A8318"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C8D871B-AEA1-4407-AEE3-47EC782250FF"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98381E61-F082-4302-B51F-5648884F998B"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D99A687E-EAE6-417E-A88E-D0082BC194CD"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B353CE99-D57C-465B-AAB0-73EF581127D1"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7431ABC1-9252-419E-8CC1-311B41360078"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6897676D-53F9-45B3-B27F-7FF9A4C58D33"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E28F226A-CBC7-4A32-BE58-398FA5B42481"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76C24D94-834A-4E9D-8F73-624AFA99AAA2"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:7.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57B5CF5A-D48E-4AD0-91E2-F5BDD44B7A66"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:7.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6F33DBA-25BA-4A29-A80C-A9FB96FFE721"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4DF2B9A2-8CA6-4EDF-9975-07265E363ED2"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7DA6A5AF-2EBE-4ED9-B312-DCD9D150D031"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22D095ED-9247-4133-A133-73B7668565E4"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "871A5C26-DB7B-4870-A5B2-5DD24C90B4A7"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12A809B2-2771-4780-9E0D-6A7B4A534CFB"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B76AA310-FEC7-497F-AF04-C3EC1E76C4CC"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17F256A9-D3B9-4C72-B013-4EFD878BFEA8"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B09ACF2D-D83F-4A86-8185-9569605D8EE1"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC10D919-57FD-4725-B8D2-39ECB476902F"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1272DF03-7674-4BD4-8E64-94004B195448"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1CA946D-1665-4874-9D41-C7D963DD1F56"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:7.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C450C83-695F-4408-8B4F-0E7D6DDAE345"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:7.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3707B08D-8A78-48CB-914C-33A753D13FC7"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3ADDB02D-F377-43CE-B0A8-FC6C7D5CFABC"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15D3CC6E-3A8F-4694-B3CC-0DB12A3E9A0F"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E881C927-DF96-4D2E-9887-FF12E456B1FB"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB096D5D-E8F6-4164-8B76-0217B7151D30"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01ED4F33-EBE7-4C04-8312-3DA580EFFB68"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "825ECE2D-E232-46E0-A047-074B34DB1E97"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:jboss_core_services:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2466282-51AB-478D-9FF4-FA524265ED2E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "142AD0DD-4CF3-4D74-9442-459CE3347E3A"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F4CFF558-3C47-480D-A2F0-BABF26042943"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D7EE4B6-A6EC-4B9B-91DF-79615796673F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "51EF4996-72F4-4FA4-814F-F5991E7A8318"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server_workstation:7.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DC7808D1-B267-4361-8187-5AB70B64179A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1691C7CE-5CDA-4B9A-854E-3B58C1115526",
              "versionEndIncluding": "2.4.48"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A930E247-0B43-43CB-98FF-6CE7B8189835"
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80E516C0-98A4-4ADE-B69F-66A772E2BAAA"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C2089EE-5D7F-47EC-8EA5-0F69790564C4"
            },
            {
              "criteria": "cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FE996B1-6951-4F85-AA58-B99A379D2163"
            },
            {
              "criteria": "cpe:2.3:a:netapp:storagegrid:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8ADFF451-740F-4DBA-BD23-3881945D3E40"
            },
            {
              "criteria": "cpe:2.3:o:broadcom:brocade_fabric_operating_system_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2748912-FC54-47F6-8C0C-B96784765B8E"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:f5:f5os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80A2EFAB-4D06-4254-B2FE-5D1F84BDFD3A",
              "versionEndIncluding": "1.1.4",
              "versionStartIncluding": "1.1.0"
            },
            {
              "criteria": "cpe:2.3:o:f5:f5os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBACFB6F-D57E-4ECA-81BB-9388E64F7DF3",
              "versionEndIncluding": "1.2.1",
              "versionStartIncluding": "1.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B095CC03-7077-4A58-AB25-CC5380CDCE5A"
            },
            {
              "criteria": "cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFC79B17-E9D2-44D5-93ED-2F959E7A3D43"
            },
            {
              "criteria": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD04BEE5-E9A8-4584-A68C-0195CE9C402C"
            },
            {
              "criteria": "cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82EA4BA7-C38B-4AF3-8914-9E3D089EBDD4"
            },
            {
              "criteria": "cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9C9BC66-FA5F-4774-9BDA-7AB88E2839C4"
            },
            {
              "criteria": "cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F69B9A5-F21B-4904-9F27-95C0F7A628E3"
            },
            {
              "criteria": "cpe:2.3:a:oracle:secure_global_desktop:5.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DA11710-9EA8-49B4-8FD1-3AEE442F6ADC"
            },
            {
              "criteria": "cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3E503FB-6279-4D4A-91D8-E237ECF9D2B0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:ruggedcom_nms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "414A7F48-EFA5-4D86-9F8D-5A179A6CFC39"
            },
            {
              "criteria": "cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEF5E6CF-BBA5-4CCF-ACB1-BEF8D2C372B8",
              "versionEndExcluding": "1.0.3"
            },
            {
              "criteria": "cpe:2.3:a:siemens:sinema_remote_connect_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98CC9C9A-FE14-4D50-A8EC-C309229356C8",
              "versionEndExcluding": "3.1"
            },
            {
              "criteria": "cpe:2.3:a:siemens:sinema_remote_connect_server:3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D889831F-64D0-428A-A26C-71152C3B9974"
            },
            {
              "criteria": "cpe:2.3:a:siemens:sinema_server:14.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0A5CC25-A323-4D49-8989-5A417D12D646"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A686FAF0-1383-4BBB-B7F5-CBCCAB55B356",
              "versionEndIncluding": "5.19.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org",
  "cisaRequiredAction": "Apply updates per vendor instructions.",
  "cisaVulnerabilityName": "Apache HTTP Server-Side Request Forgery (SSRF)"
}