CVE-2022-36760 impact on SteelHead Platforms

Solution Number:
S37279
Last Modified:
2023-03-12
Description
CVE-2022-36760
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server 2.4 versions - 2.4.54 and prior versions.
Issue
Are SteelHead platforms affected by CVE-2022-36760 vulnerability?
Solution
Though SteelHead appliances are using the affected Apache version, we are not affected by this vulnerability. The Apache version will still be upgraded with a future SteelHead release.
Environment
SteelHead Platforms
Attachments
NOTICE: Riverbed® product names have changed. Please refer to the Product List for a complete list of product names.
Can't find an answer? Create a case