CVE-2022-28330
published 2022-06-09CVE-2022-28330: Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
3.40%
87.6th percentile
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | <= 2.4.53 | — |
| apache_software_foundation | apache_http_server | Apache HTTP Server – 2.4.53 | — |
| debian | apache2 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w8xx-cjqj-c9jq: Apache HTTP Server 2
ghsa_unreviewed·2022-06-10
CVE-2022-28330 [MEDIUM] CWE-125 GHSA-w8xx-cjqj-c9jq: Apache HTTP Server 2
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
OSV
CVE-2022-28330: Apache HTTP Server 2
osv·2022-06-09·CVSS 5.3
CVE-2022-28330 [MEDIUM] CVE-2022-28330: Apache HTTP Server 2
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
CISA ICS
Hitachi Energy Service Suite
cisa_ics·2025-05-13·CVSS 9.8
[CRITICAL] Hitachi Energy Service Suite
ICS Advisory
##
Hitachi Energy Service Suite
Release DateMay 13, 2025
Alert CodeICSA-25-133-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Service Suite
- Vulnerabilities: Use of Less Trusted Source, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Integer Overflow or Wraparound, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Exposure of Sensitive Information to an Unauthorized Actor, Memory Allocation with Excessive Size Value, Out-of-bounds Read, Uncontrolled Resource Consumption, Improper Resource Shutdown or Re
Red Hat
httpd: mod_isapi: out-of-bounds read
vendor_redhat·2022-06-08·CVSS 5.3
CVE-2022-28330 [MEDIUM] CWE-125 httpd: mod_isapi: out-of-bounds read
httpd: mod_isapi: out-of-bounds read
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
An out-of-bounds read vulnerability was found in the mod_isapi module of httpd. The issue occurs when httpd is configured to process requests with the mod_isapi module.
Statement: Httpd, as shipped with Red Hat Enterprise Linux 6, 7, 8, 9, and RHSCL, is not affected by this flaw because it does not ship the mod_isapi module. The mod_isapi module is shipped by Windows systems only.
Package: httpd (Red Hat Enterprise Linux 6) - Not affected
Package: httpd (Red Hat Enterprise Linux 7) - Not affected
Package: httpd:2.4/httpd (Red Hat Enterprise Linux 8) - Not affected
Package: httpd (Red Hat Enterprise Linux 9) - Not
Debian
CVE-2022-28330: apache2 - Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when con...
vendor_debian·2022·CVSS 5.3
CVE-2022-28330 [MEDIUM] CVE-2022-28330: apache2 - Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when con...
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2022/06/08/3https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://security.netapp.com/advisory/ntap-20220624-0005/http://www.openwall.com/lists/oss-security/2022/06/08/3https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://security.netapp.com/advisory/ntap-20220624-0005/
2022-06-09
Published