Seiden Group
Modern Development & Open Source for IBM i
  • Link to LinkedIn
  • Link to Mail
  • Home
  • Seiden PHP+
    • Seiden PHP+
    • Install & Learn
    • SmartSupport
    • PHP Migrations & Upgrades
    • Success Stories
    • Free PHP Assessment
    • Documentation
    • What’s New (Changelog)
  • IBM i Services
    • Development
    • Training & Mentoring
    • Open Source Setup & Upgrades
    • SSL/TLS Install & Learn
    • Performance
  • Support
    • Open Source & PHP
    • VS Code for i
    • Developer Support
    • Support Success Stories
  • VS Code for i
    • Support
    • Training
    • Code for i Resource Guide
    • Getting Started Videos
    • Code for IBM i Fridays
  • Free Stuff
    • IBM i Strategy & Tips
    • PHP Upgrade Assessment
    • CNX Valence Assessment
    • VS Code for IBM i Resources
    • Code for IBM i Fridays
    • QCachegrind Download
    • PHP Toolkit for IBM i Resources
    • Qshell on i Library
  • Blog
  • About
    • About Our Team
    • About Alan Seiden
    • Speakers & Sessions
    • In the News
  • Contact
  • 201.447.2437
  • Search
  • Menu Menu

Seiden Group Blog

Finding Security Fixes for Apache on IBM i

February 9, 2024/2 Comments/in Apache, APIs & Web Services /by Alan Seiden

API and web security for IBM iThe Apache-based IBM HTTP Server for i is a vital defense in web and API security for IBM i. As such, it requires regular attention.

IBM Support’s PCI Compliance web page is a resource we use to help our clients protect their systems.

Even if your organization does not process, store, or transmit credit card information, applying the PTFs recommended for PCI compliance constitutes a general best practice for IBM i web and API security.

As we’ve begun helping more clients with Apache security, we recommend PTFs to protect them from vulnerabilities, starting with those rated “important” by the National Vulnerability Database (NVD), including these examples:

HTTP Request Smuggling

HTTP Request Smuggling is a technique that can let a bad actor bypass security controls, gain access to sensitive data, and compromise other application users. One particular bug that may allow Request Smuggling has been described by the NVD as “Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body,” creating the possibility of exploitation.

IBM offers PTF fixes for IBM i 7.5, 7.4, 7.3, and 7.2.

Specially Crafted HTTP/2 Request Causes Crash

Several vulnerabilities have been fixed that relate to handling HTTP/2 requests, including:

“A specially crafted value for the ‘Cache-Digest’ header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via “H2Push off” will mitigate this vulnerability for unpatched servers.”

IBM offers PTF fixes for IBM i 7.4 and 7.3. The issues were already remediated in IBM i 7.5, another smart reason to stay current with system releases.

Malicious Request Headers Cause Errors

“The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.”

IBM offers PTF fixes for IBM i 7.3 and 7.2. The issues were already remediated in IBM i 7.4 and higher.

Stay Safe Out There

The landscape for web server and API security evolves quickly. While high-risk vulnerabilities like these happen infrequently, it’s important to schedule regular security check-ups for your web server to remain protected. Traditional IBM i security is not enough.

We’re helping clients stay on top of web server security. If you’d like to set up a schedule with us, too, let me know.

Tags: Apache, API, IBM i, security
Share this entry
  • Share on Facebook
  • Share on X
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Reddit
  • Share by Mail
https://www.seidengroup.com/wp-content/uploads/2017/03/SeidenLogo-180.png 0 0 Alan Seiden https://www.seidengroup.com/wp-content/uploads/2017/03/SeidenLogo-180.png Alan Seiden2024-02-09 11:24:352024-02-15 12:32:41Finding Security Fixes for Apache on IBM i
Alan Seiden

About Alan Seiden

Alan works to preserve your investment in IBM enterprise systems by designing and implementing modernization strategies that leverage your existing business logic.

With a passion ...Read More

2 replies
  1. Paul Nicolay
    Paul Nicolay says:
    August 11, 2026 at 7:42 am

    Hi,

    Unfortunately, IBM replaced the information on the link https://www.ibm.com/support/pages/node/1170946 with some generic CVE tool that no longer provides clear feedback on the Apache security fixes that exist for IBM i.

    Kind regards,
    Paul

    Reply
    • Alan Seiden
      Alan Seiden says:
      August 11, 2026 at 10:10 am

      Thank you, Paul. I noticed this, too, and was going to ask you if you knew about it.

      Reply

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

SUBSCRIBE
Open Thinking
Monthly IBM i Strategy & Tips
  • This field is for validation purposes and should be left unchanged.

IBM i Development

  • RPG, COBOL, SQL, Node,
    PHP, Python, Valance, etc.
  • Modernization. Integration.
  • Web and API Solutions
  • Legacy Maintenance
    ...
LET'S GET IT DONE!

Recent Posts

  • Do You Need IBM i Observability?
  • PHP 8.6 is Coming Soon to IBM i
  • Safer npm installation is on the way for Node.js (and all JavaScript)
  • Access Modern Security for IBM i and Connected Web Environments
  • IBM i: A Natural Platform for Agentic AI
  • PHP on IBM i in 2026: The Modernization Engine
  • Your “AS/400” Is a Modern IBM i Platform
  • MCP + AI for IBM i Teams (with a MongoDB example)
  • GnuPG PHP Extension for IBM i: Now Included with Seiden Support
  • Getting Started with Code for IBM i: A Lunch & Learn Video

SEIDEN GROUP: Modern Development & Open Source for IBM i

Home   |   Seiden PHP+   |   IBM i Services  |   Support   |   VS Code for i   |   Free Stuff   |   Blog  |   Privacy Policy  |   Contact         201.447.2437

© 2026 Seiden Group, LLC
  • Link to LinkedIn
  • Link to Mail
Link to: Our Favorite ibm_db2 Settings for PHP Link to: Our Favorite ibm_db2 Settings for PHP Our Favorite ibm_db2 Settings for PHP Link to: APCu Extension Added to Seiden PHP+ Link to: APCu Extension Added to Seiden PHP+ APCu Extension Added to Seiden PHP+
Scroll to top Scroll to top Scroll to top