Fixes are available
PH42862: Multiple vulnerabilities in IBM HTTP Server used by WebSphere Application Server (CVE-2021-44790 CVSS 9.8 and more)
PH41945: IHS connections not accepted with maxrequestsperchild > 0
PH43122: Vulnerability in IBM HTTP Server used by IBM WebSphere Application Server (CVE-2022-23852 CVSS 9.8 and more)
PH44393:crash in ap_scan_http_field_content with interim fix IFPH43122
PH44271: Vulnerability in IBM HTTP Server used by IBM WebSphere Application Server due to Expat (CVE-2022-25315 CVSS 7.8 and more)
PH44829:Multiple vulnerabilities in IBM HTTP Server used by IBM WebSphere Application Server (CVE-2022-22720 CVSS 7.3 and more)
APAR status
Closed as program error.
Error description
On Linux and z/OS, if MaxRequestsPerChild is non-zero, IHS may get into a state where no processes are available to accept new client connections.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All users of IBM HTTP Server on Linux and * * zOS * **************************************************************** * PROBLEM DESCRIPTION: IHS may hang with MaxRequestsPerChild > * * 0 * **************************************************************** * RECOMMENDATION: * **************************************************************** IHS may stop responding then stop accepting no new connections. ps output shows no request handling processes (with appx ThreadsPerChild threads) are running, only utility daemons.
Problem conclusion
The code was fixed to properly count the number of "active daemons" when children exit due to MaxRequestsPerChild. The fix for this APAR is targeted for inclusion in IBM HTTP Server fix packs and 9.0.5.11. For more information, see 'Recommended Updates for WebSphere Application Server': https://www.ibm.com/support/pages/node/715553
Temporary fix
Comments
APAR Information
APAR number
PH41945
Reported component name
IBM HTTP SERVER
Reported component ID
5724J0801
Reported release
900
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2021-11-08
Closed date
2022-01-11
Last modified date
2022-01-11
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
IBM HTTP SERVER
Fixed component ID
5724J0801
Applicable component levels
R900 PSY
UP
Document Information
Modified date:
04 May 2022