Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.
We have discovered 321,526 live websites that are affected by CVE-2017-9798.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 321,526 live websites (13% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 57 versions ( 47% of all versions) |
| 41,860 websites | |
| 102,998 websites | |
| 28,908 websites | |
| 22,546 websites | |
| 13,990 websites | |
| 8,660 websites | |
| 8,658 websites | |
| 8,335 websites | |
| 7,343 websites | |
| 6,684 websites |
| .com | 150,421 websites |
| .de | 22,884 websites |
| .net | 12,751 websites |
| .ru | 12,024 websites |
| .info | 9,029 websites |
| .org | 8,935 websites |
| .jp | 7,145 websites |
| .cz | 7,120 websites |
| .it | 5,748 websites |
| .nl | 4,707 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.***********.com | *** | ||
| *********.******.net | *,*** | ||
| ****.**.pl | *,*** | ||
| ******.com | *,*** | ||
| ********.********.de | *,*** | ||
| ******.****************.com | *,*** | ||
| **********.com | *,*** | ||
| ******.**.pl | *,*** | ||
| ****.**********.com | *,*** | ||
| *****.**********.com | *,*** |