Vulnerability in Apache HTTP Server 2.4.64 and older in Siteminder Sharepoint Agent 12.8.x
search cancel

Vulnerability in Apache HTTP Server 2.4.64 and older in Siteminder Sharepoint Agent 12.8.x

book

Article ID: 407361

calendar_today

Updated On:

Products

CA Single Sign On Agents (SiteMinder) SITEMINDER

Issue/Introduction

The Siteminder Agent for Sharepoint r12.8.x ships bundled with an instance of Apache HTTP Server.  The following is a list of Apache HTTP Server versions by Siteminder Agent for Sharepoint version:

Agent for Sharepoint r12.8.7:     Apache HTTP Server 2.4.54
Agent for Sharepoint r12.8.8:     Apache HTTP Server 2.4.58

A number of Common Vulnerabilities and Exposures (CVE's) published for Apache HTTPS Server 2.4.64 and older.  These CVE's are remediated in Apache HTTP Server 2.4.65.

For Apache HTTP Server on Siteminder Access Gateway, see the following KB's:

Vulnerability in Apache 2.4.64 and older in Siteminder Access Gateway r12.8.8.1 and Older

Vulnerability in Apache 2.4.64 and older in Siteminder Access Gateway r12.9

Environment

PRODUCT: SiteMinder

COMPONENT: Agent for Sharepoint

VERSION: 12.8.7 & 12.8.8

OPERATING SYSTEM: ANY

Cause

The following CVE was published for Apache HTTP Server 2.4.64:

CVE-2025-54090: Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64

SEVERITY: Moderate

DESCRIPTION: A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true".

IMPACTED: 2.4.64

REMEDIATED: 2.4.65

There are CVE's published for HTTP Server 2.4.63 and older as well.  CVE's are referenced in "Additional Information" below.

Resolution

This solution only applies to Apache HTTP Server on the Sharepoint Agent r12.8.x.  For Apache on Siteminder Access Gateway, review the following KB's:

Vulnerability in Apache 2.4.64 and older in Siteminder Access Gateway r12.8.8.1 and Older

Vulnerability in Apache 2.4.64 and older in Siteminder Access Gateway r12.9

How to Verify the version of Apache HTTP Server Installed on Siteminder Agent for Sharepoint

 

WINDOWS

1. Stop the running Sharepoint Agent

2. Using File Explorer, navigate to the Sharepoint Agent installation directory

Default: <Install_Dir>\CA\Agent-for-SharePoint\

3. Back-up the original '\httpd' directory <httpd_orig>

<Install_Dir>\CA\Agent-for-SharePoint\httpd

4. Unzip the attached "httpd_2465_win64_128801andBelow.zip" and copy the 'httpd' folder to <Install_Dir>\CA\Agent-for-SharePoint\

5. Copy the the '/conf' directory from the original  "<httpd_orig>\conf"  into  <Install_Dir>\CA\Agent-for-SharePoint\/httpd

6. Copy the the 'configssl.bat' file from the original  "<httpd_orig>\bin"  into  <Install_Dir>\CA\Agent-for-SharePoint\/httpd\bin

8. Upgrade to OpenSSL 1.0.2zl as per KB385668: Vulnerabilities in OpenSSL 1.0.2zk and Older on Siteminder Access Gateway r12.8.x

9. Start the Sharepoint Agent


LINUX

1. Stop the running Sharepoint Agent

2. Navigate to the Sharepoint Agent installation directory 

Default: <Install_Dir>/CA/Agent-for-SharePoint/

3. Back-up the original '/httpd' directory <httpd_orig>

<Install_Dir>/CA/Agent-for-SharePoint/httpd

4. Unzip the attached 'httpd_2465_linux_1280801andBelow.zip' file and copy the '/httpd' folder to <Install_Dir>/CA/Agent-for-SharePoint/

5. Copy the following files from the original  <httpd_orig>  into  <Install_Dir>/CA/Agent-for-SharePoint/

cp -r httpd_orig/conf  httpd/
cp httpd_orig/bin/apachectl httpd/bin/
cp httpd_orig/bin/apr-1-config  httpd/bin/
cp httpd_orig/bin/apu-1-config httpd/bin/
cp httpd_orig/bin/apxs httpd/bin/
cp httpd_orig/bin/envvars httpd/bin/
cp httpd_orig/bin/envvars-std  httpd/bin/

6. Upgrade to OpenSSL 1.0.2zl as per KB385668: Vulnerabilities in OpenSSL 1.0.2zk and Older on Siteminder Access Gateway r12.8.x

7. Start the Sharepoint Agent

Additional Information

How to Verify the version of Apache HTTP Server Installed on Siteminder Agent for Sharepoint

KB385668: Vulnerabilities in OpenSSL 1.0.2zk and Older on Siteminder Access Gateway r12.8.x

Vulnerability in Apache 2.4.64 and older in Siteminder Access Gateway r12.8.8.1 and Older

Vulnerability in Apache 2.4.64 and older in Siteminder Access Gateway r12.9

Apache HTTP Server 2.4 vulnerabilities

Upgrading to Apache HTTP Server 2.4.64 will remediate the following CVE's:

CVE-2025-54090
CVE-2024-42516
CVE-2024-43204
CVE-2024-43394
CVE-2024-47252
CVE-2025-23048
CVE-2025-49630
CVE-2024-49812
CVE-2024-40898
CVE-2024-40725
CVE-2025-54090
CVE-2024-40898
CVE-2023-38709
CVE-2024-36387
CVE-2024-24795
CVE-2024-27316
CVE-2023-31122
CVE-2023-43622
CVE-2023-45802
CVE-2023-25690
CVE-2023-27522
CVE-2006-20001
CVE-2022-36760
CVE-2022-37436
CVE-2022-26377
CVE-2022-28330
CVE-2022-28614
CVE-2022-28615
CVE-2022-29404
CVE-2022-30522
CVE-2022-30556
CVE-2022-31813
CVE-2022-22719
CVE-2022-22720
CVE-2022-22721
CVE-2022-23943
CVE-2021-44224
CVE-2021-44790
CVE-2021-42013
CVE-2021-41524
CVE-2021-41773
CVE-2021-33193
CVE-2021-34798
CVE-2021-36160
CVE-2021-39275
CVE-2021-40438
CVE-2019-17567
CVE-2020-13938
CVE-2020-13950
CVE-2020-35452
CVE-2021-26690
CVE-2021-26691
CVE-2021-30641
CVE-2021-31618
CVE-2020-11984
CVE-2020-11993
CVE-2020-9490

Attachments

httpd_2465_linux_1280801andBelow.zip get_app
httpd_2465_win64_128801andBelow.zip get_app