Endpoint Protection

 View Only
  • 1.  Apache Web Server 2.4.48

    Posted Sep 02, 2021 04:22 PM
    Hello,

    Can you share when SEPM will use Apache Web Server 2.4.48?  There are concerns over the existing vulns that 14.3 RU2 SEPM is using (apache version 2.4.43)

    Thank You
    Rob Trimble
    TechData Support Services


  • 2.  RE: Apache Web Server 2.4.48

    Broadcom Employee
    Posted Oct 04, 2021 04:55 PM
    Apache was updated to 2.4.48.694 in SEP 14.3 RU3 release.


  • 3.  RE: Apache Web Server 2.4.48

    Posted Oct 05, 2021 02:10 PM
    Since this update our vulnerability scanner is now saying it needs to be updated to 2.4.49.  Is this update planned anytime soon?


  • 4.  RE: Apache Web Server 2.4.48

    Broadcom Employee
    Posted Oct 05, 2021 02:13 PM

    Hi David,

    Vulnerability Scanners only look at what version of Apache is deployed not if the impacted modules are active or used. 14.3 RU4 will update Apache to 2.4.49 and has an eta of January right now.



    ------------------------------
    John Owens
    Strategic Support Engineer | Symantec Endpoint Security Division (SES)
    Broadcom Software
    ------------------------------



  • 5.  RE: Apache Web Server 2.4.48

    Posted Oct 06, 2021 02:39 AM
    I guess 2.4.49 will be replaced with 2.4.50?

    https://httpd.apache.org/security/vulnerabilities_24.html


  • 6.  RE: Apache Web Server 2.4.48

    Posted Nov 03, 2021 08:27 AM
    Any update on a version that will update Apache to 2.4.49 or later?


  • 7.  RE: Apache Web Server 2.4.48

    Broadcom Employee
    Posted Nov 03, 2021 10:03 AM
    14.3 RU4 has an eta of January right now. It will have an updated version of Apache. It won't be 2.4.49 due to Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project.  Likely will be 2.4.51 or later.

    ------------------------------
    John Owens
    Strategic Support Engineer | Symantec Endpoint Security Division (SES)
    Broadcom Software
    ------------------------------