SEP Vulnerability Assessment for Apache HTTP Server 2.4
search cancel

SEP Vulnerability Assessment for Apache HTTP Server 2.4

book

Article ID: 404568

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

You request to know if the Symantec Endpoint Protection Manager (SEPM) is impacted by any of the following vulnerabilities:

CVE-2024-42516
CVE-2024-43204
CVE-2024-43394
CVE-2024-47252
CVE-2025-23048
CVE-2025-49630
CVE-2025-49812
CVE-2025-53020
CVE-2025-55753
CVE-2025-58098
CVE-2025-59775
CVE-2026-23918
CVE-2026-33006
CVE-2026-28780
CVE-2026-29168
CVE-2026-29169
CVE-2026-33007
CVE-2026-33523
CVE-2026-33857
CVE-2026-34032
CVE-2026-34059

Environment

SEPM 14.3 RU8 and newer

Resolution

  • CVE-2024-42516 - SEPM is not impacted by CVE-2024-42516 because it does not allow unauthorized components to act as backend/content generator (e.g. content-type response headers).
  • CVE-2024-43204 - SEPM is not impacted by CVE-2024-43204 because it does not load mod_header; also mod_proxy is only loaded when reverse proxy is configured
  • CVE-2024-43394 - SEPM is not impacted by CVE-2024-43394 because mod_rewrite is not used.
  • CVE-2024-47252 - SEPM is not impacted by CVE-2024-47252 because the SEPM Apache does not use CustomLog with the format "%{varname}x" or "%{varname}c"
  • CVE-2025-23048 - SEPM is not impacted by CVE-2025-23048 because SEPM Apache does not use TLS 1.3
  • CVE-2025-49630 - SEPM is not impacted by CVE-2025-49630 because SEPM does not use mod_proxy_http2
  • CVE-2025-49812 - SEPM is not impacted by CVE-2025-49812 because SEPM Apache does not enable the TLS Upgrade option (i.e. SSLEngine optional)
  • CVE-2025-53020 - SEPM is not impacted by CVE-2025-53020 because HTTP/2 is not enabled
  • CVE-2025-55753 - SEPM is not impacted by CVE-2025-55753
  • CVE-2025-58098 - SEPM is not impacted by CVE-2025-58098
  • CVE-2025-59775 - SEPM is not impacted by CVE-2025-59775
  • CVE-2026-23918 - No impact on SEPM, the mod_http2 module is neither shipped nor loaded by SEPM's Apache instance.
  • CVE-2026-33006 - No impact on SEPM, the directive #LoadModule auth_digest_module modules/mod_auth_digest.so is commented out
  • CVE-2026-28780 - No impact on SEPM, the directive #LoadModule proxy_ajp_module modules/mod_proxy_ajp.so is commented out and disabled in the production configuration.
  • CVE-2026-29168 - No impact on SEPM, the mod_md module is completely absent from SEPM's Apache configuration.
  • CVE-2026-29169 - No impact, SEPM does not use WebDAV. The directive #LoadModule dav_lock_module modules/mod_dav_lock.so is commented out
  • CVE-2026-33007 - No impact on SEPM, this module is not loaded or referenced anywhere in SEPM's Apache configuration.
  • CVE-2026-33523 - No impact, SEPM's Apache instance only communicates with its own trusted internal backend (Tomcat/PHP running on localhost) via mod_fcgid and mod_isapi.
  • CVE-2026-33857 - No impact on SEPM, the directive #LoadModule proxy_ajp_module modules/mod_proxy_ajp.so is commented out.
  • CVE-2026-34032 - No impact on SEPM, the directive #LoadModule proxy_ajp_module modules/mod_proxy_ajp.so is commented out.
  • CVE-2026-34059 - No impact on SEPM, the directive #LoadModule proxy_ajp_module modules/mod_proxy_ajp.so is commented out.
  • CVE-2026-33006 - No impact on SEPM, the directive #LoadModule auth_digest_module modules/mod_auth_digest, so is commented out.