Hi, all
I have an Apache reverse proxy server (v2.2.21) redirects traffic from http to https for a back end web server. I don’t know the exact version of the back end Apache web server because Oracle changed the version number but I am sure it is below v2.2.21.
Our vulnerability scan shows that the web site has:
Apache httpd Range header remote DoS (CVE-2011-3192) (apache-httpd-cve-2011-3192)
My question is that front end of Apache reverse proxy hide the back end web server problem, isn’t it? If not, how do I fix the problem besides to upgrade the version of back end Apache web server? Thanks.
Ryan Jiang
Liz Claiborne, Inc.