CVE-2021-34798

Modified
Published: 16 Sept 2021, 14:40
Last modified:04 Aug 2024, 00:26

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
10.29% MEDIUM
10% probability -1.67%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Sept 2021, 14:40
Published
Vulnerability first disclosed
04 Aug 2024, 00:26
Last Modified
Vulnerability information updated

Description

Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 10.29% Percentile: 93%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • apache software foundationapache http server

    ≥ Apache HTTP Server 2.4, ≤ 2.4.48

  • UnknownHTTP Server

    ≤ 2.4.48

  • broadcombrocade_fabric_operating_system

    na

  • debiandebian_linux

    9.0 | 10.0 | 11.0

  • fedoraprojectfedora

    34 | 35

  • netappcloud_backup

    na

  • netappclustered_data_ontap

    na

  • netappstoragegrid

    na

  • oraclecommunications_cloud_native_core_network_function_cloud_native_environment

    1.10.0

  • oracleenterprise_manager_base_platform

    13.4.0.0 | 13.5.0.0

  • oraclehttp_server

    12.2.1.3.0 | 12.2.1.4.0

  • oracleinstantis_enterprisetrack

    17.1 | 17.2 | 17.3

  • oraclepeoplesoft_enterprise_peopletools

    8.58

  • oraclezfs_storage_appliance_kit

    8.8

  • siemenssinema_remote_connect_server

    < 3.1

  • siemenssinema_server

    14.0

  • tenabletenable.sc

    ≤ 5.19.1

References (17)