Security Bulletin: IBM HTTP Server (powered by Apache) for IBM i is vulnerable to a remote attacker causing a denial of service, executing arbitrary code, and mapping URLs to filesystem locations due to multiple vulnerabilities.

​IBM HTTP Server (powered by Apache) for IBM i is vulnerable to a remote attacker causing a denial of service due to NULL pointer dereference [CVE-2024-38477], executing arbitrary code due to an encoding issue in mod_rewrite [CVE-2024-38474], and improper escaping in mod_rewrite resulting in access to files [CVE-2024-38475] as described in the vulnerability details section. This bulletin identifies the steps to take to address the vulnerabilities as described in the remediation/fixes section. Read More 

October 15th Member Meeting tlake

​Our October meeting will be provided by Barbara Morris, talking to us about what’s new in RPG with 7.4 and 7.5 PTFs, with new and updated built-in functions and opcodes, improved handling for UTF-8 data, and an option to pass “any type” parameters as strings. RSVP and review addition information here: https://www.quser.org/content/quser-october-2024 Read More 

Verified by MonsterInsights