Hewlett-Packard released security bulletins HPSBUX03102 and HPSBUX03150 for multiple vulnerabilities in the HP-UX Apache Web Server Suite, affecting bundled Apache HTTP Server, Tomcat Servlet Engine, and PHP components. Impacted systems could be vulnerable to remote code execution, denial of service, HTTP request smuggling, access-control bypass, man-in-the-middle attacks, and unauthorized file or data access; the most severe cited issue, PHP CVE-2014-3515, carries a CVSS v2 score of 7.5 and permits remote arbitrary code execution.
For HP-UX B.11.31, HP advised upgrading Web Server Suite to version 4.02 or later, including Apache 2.2.15.20, Tomcat 6.0.39.02, and PHP 5.4.11.04. For HP-UX B.11.23 systems using Web Server Suite 3.29 or earlier, Tomcat 5.5.36.01 or earlier, or PHP 5.2.17.03 or earlier, HP recommended Web Server Suite 3.30 or later, with Apache 2.2.15.21, Tomcat 5.5.36.02, and PHP 5.2.17.04.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Hewlett-Packard published security bulletin HPSBUX03150 (SSRT101681 rev.1) for vulnerabilities affecting HP-UX B.11.23 Apache Web Server Suite, Tomcat, and PHP components. HP recommended upgrading to HP-UX Web Server Suite v3.30 or later to address denial-of-service, request-smuggling, man-in-the-middle, and data-modification risks.
HP released security bulletin HPSBUX03102 (SSRT101681 rev.1) for vulnerabilities in the HP-UX Apache Web Server Suite, Tomcat, and PHP on HP-UX B.11.31. It directed affected customers to upgrade to Web Server Suite v4.02 or later, addressing issues including remote code execution, denial of service, request smuggling, and file access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
marc.info
Open sourcemarc.info
Open sourcesoftware.hp.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.