CVE-2015-3185

The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.


We have discovered 945,744 live websites that are affected by CVE-2015-3185.

Test my site




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains945,744 live websites (29.98% of Apache install base)
Vulnerable Versions
  • from 0 before 2.4.14
Vulnerable Versions Count101 versions ( 68.71% of all versions)



Details

  • Published - Jul 21, 2015
  • Updated - Aug 6, 2024

CVE-2015-3185 usage by Country

United States273,414 websites



Taiwan109,312 websites
Germany90,273 websites
Japan54,269 websites
France42,325 websites
Netherlands39,667 websites
Russia37,383 websites
Singapore24,404 websites
Czech Republic24,045 websites
GB20,848 websites

CVE-2015-3185 usage by TLD

.com404,967 websites
.de64,753 websites
.net39,347 websites
.org33,202 websites
.ru32,765 websites
.nl28,611 websites
.cz19,603 websites
.jp16,450 websites
.it15,216 websites
.info15,011 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2015-3185

Top websites that are affected by CVE-2015-3185. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
*********.*************.se United States***
********.*********.com Singapore*,***
******************.com United States*,***
*********.******.net United States*,***
****.com United States*,***
********.com United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
See full domain list

FAQ

A total of 945,744 websites have been identified as vulnerable to CVE-2015-3185, discovered through global website indexing conducted by WebTechSurvey.
Apache is susceptible to CVE-2015-3185 vulnerability.
Apache versions before 2.4.14 are vulnerable to CVE-2015-3185.
Version 2.4.14 of Apache addresses the CVE-2015-3185 security vulnerability.

References