CVE-2015-3185

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.


We have discovered 288,713 live websites that are affected by CVE-2015-3185.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains288,713 live websites (11% of Apache install base)
Vulnerable Versions
  • from 2.4 through 2.4.14
Vulnerable Versions Count13 versions ( 11% of all versions)



Details

  • Published - Jul 20, 2015
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2015-3185
United States103,395 websites



Germany20,554 websites
Netherlands18,381 websites
Japan17,233 websites
France14,990 websites
Russia10,472 websites
Italy7,905 websites
Singapore7,818 websites
Czech Republic7,457 websites
Korea, South5,875 websites

Website Distribution by TLD

Number of websites using CVE-2015-3185
.com131,166 websites
.nl13,962 websites
.de12,620 websites
.net11,849 websites
.org11,505 websites
.ru8,871 websites
.it6,563 websites
.cz6,031 websites
.fr4,799 websites
.jp4,221 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2015-3185

Top websites that are affected by CVE-2015-3185. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******************.com United States*,***
*******.**.com United States*,***
****.com United States*,***
********.com United States*,***
*.******.***.***.br Brazil*,***
*************.com GB*,***
*.*****.***.***.br Brazil*,***
******.com France*,***
**************.**.uk GB*,***
****.**.com United States*,***
See full domain list

FAQ

A total of 288,713 websites have been identified as vulnerable to CVE-2015-3185, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2015-3185 vulnerability.
Apache versions up to 2.4.14 are vulnerable to CVE-2015-3185.
CVE-2015-3185 is resolved in version 2.4.14 of Apache.

References