> Source: [sk182899](https://support.checkpoint.com/results/sk/sk182899)

# sk182899 - Check Point response to Apache HTTP CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-39884

| Property | Value |
|----------|-------|
| Solution ID | sk182899 |
| Date Created | 2024-12-05 |
| Last Modified | 2025-03-13 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Spark Firewall (Locally Managed) |
| Versions | R81.20, R81.10 (EOS), R81.20, R81.10.X, R81 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- These issues were reported in the Apache HTTP Server ?version 2.4.60 and lower:

1. [CVE-2024-38473](https://www.cve.org/CVERecord?id=CVE-2024-38473) - Apache HTTP Server: proxy encoding problem
2. [CVE-2024-38474](https://www.cve.org/CVERecord?id=CVE-2024-38474) - Apache HTTP Server: weakness with encoded question marks in backreferences
3. [CVE-2024-38475](https://www.cve.org/CVERecord?id=CVE-2024-38475) - Apache HTTP Server: weakness in mod_rewrite when first segment of substitution matches filesystem path
4. [CVE-2024-38476](https://www.cve.org/CVERecord?id=CVE-2024-38476) - Apache HTTP Server: may use exploitable/malicious backend application output to run local handlers via internal redirect
5. [CVE-2024-38477](https://www.cve.org/CVERecord?id=CVE-2024-38477) - Apache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious request
6. [CVE-2024-39573](https://www.cve.org/CVERecord?id=CVE-2024-39573) - Apache HTTP Server: mod_rewrite proxy handler substitution
7. [CVE-2024-39884](https://www.cve.org/CVERecord?id=CVE-2024-39884) - Apache HTTP Server: source code disclosure with handlers configured via AddType

## Solution

These problems were fixed.

* In Security Gateways, Management Servers, Log Servers, and SmartEvent Servers, the fix is included in the Apache HTTP Server version 2.4.61 and higher:

  * [Check Point Quantum R82](https://support.checkpoint.com/results/sk/sk181127) and higher
  * [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 90
  * [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 171
  * [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 106

  Hotfix installation instructions:  
  Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

  Lower versions have to be upgraded to [one of the supported versions](http://www.checkpoint.com/support-services/support-life-cycle-policy/).
* In Quantum Spark Gateways, the fix is included in the Apache HTTP Server version 2.4.61 and higher:

  * [Quantum Spark R81.10.15](https://support.checkpoint.com/results/sk/sk182438) and higher

<br />

<br />

**Important Notes**

* This article applies to all Check Point web portals for various Software Blades on these Check Point servers:

  |------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  | Server                                                                                                                                                           | Web Portal                                                                                                                                                                     |
  | Security Gateways, ClusterXL Members, VSX Gateways, VSX Cluster Members, CloudGuard Network Security Gateways (applies to physical servers and virtual machines) | * Gaia Portal * Identity Awareness Captive Portal (NAC Portal) * Data Loss Prevention Portal * UserCheck Portal * Mobile Access Portal (SSL VPN Portal) * Zero Phishing Portal |
  | Security Management Servers, Multi-Domain Security Management Servers, Harmony Endpoint Security Management Servers                                              | * Gaia Portal * Web SmartConsole * SmartView * ICA Portal                                                                                                                      |
  | Dedicated Log Servers, Multi-Domain Log Servers                                                                                                                  | * Gaia Portal * Web SmartConsole * SmartView                                                                                                                                   |
  | Dedicated SmartEvent Servers                                                                                                                                     | * Gaia Portal * Web SmartConsole * SmartView                                                                                                                                   |
  | Quantum Spark Gateways                                                                                                                                           | * Identity Awareness Captive Portal (NAC Portal) * UserCheck Portal * Hotspot portal                                                                                           |

  > To see which Software Blade web portals are currently enabled, run this command in the Expert mode:
  >
  > `mpclient list | while read -r item ; do echo "Portal: $item" ; mpclient getdata "$item" ; echo "" ; done`  
  > Show / Hide example output from a Security Gateway  
  > > `
  > > Portal: DLPSenderPortal`  
  > > `
  > > Portal path prefix '/dlp' port 60796 hostname '192.168.3.57' priority 3 encrypted 1`  
  > > `
  > > `  
  > > `
  > > Portal: ExchangeRegistration`  
  > > `
  > > Portal is not configured yet`  
  > > `
  > > `  
  > > `
  > > Portal: ReverseProxyClear`  
  > > `
  > > Portal is not configured yet`  
  > > `
  > > `  
  > > `
  > > Portal: ReverseProxySSL`  
  > > `
  > > Portal is not configured yet`  
  > > `
  > > `  
  > > `
  > > Portal: SecurePlatform`  
  > > `
  > > Portal path prefix '' port 54009 hostname '192.168.3.57' priority 10 encrypted 1`  
  > > `
  > > `  
  > > `
  > > Portal: UserCheck`  
  > > `
  > > Portal path prefix '/UserCheck' port 51027 hostname '192.168.3.57' priority 1000 encrypted 0`  
  > > `
  > > `  
  > > `
  > > Portal: ZeroPhishing`  
  > > `
  > > Portal path prefix '/zph' port 59201 hostname 'zero-phishing.iaas.checkpoint.com' priority 1000 encrypted 0`  
  > > `
  > > `  
  > > `
  > > Portal: nac`  
  > > `
  > > Portal path prefix '/connect' port 57810 hostname '192.168.3.57' priority 2 encrypted 1`  
  > > `
  > > `  
  > > `
  > > Portal: nac_transparent_auth`  
  > > `
  > > Portal is not configured yet`  
  > > `
  > > `  
  > > `
  > > Portal: saml-vpn`  
  > > `
  > > Portal is not configured yet`  
  > > `
  > > `  
  > > `
  > > Portal: sslvpn`  
  > > `
  > > Portal path prefix '/sslvpn' port 54392 hostname '192.168.3.57' priority 1 encrypted 1
  > `  
  > Show / Hide example output from a Quantum Spark Gateway  
  > > `
  > > Portal: UserCheck`  
  > > `
  > > Portal is not configured yet`  
  > > `
  > > `  
  > > `
  > > Portal: hotspot`  
  > > `
  > > Portal is not configured yet`  
  > > `
  > > `  
  > > `
  > > Portal: ica`  
  > > `
  > > Portal is not configured yet`  
  > > `
  > > `  
  > > `
  > > Portal: nac`  
  > > `
  > > Portal is not configured yet`  
  > > `
  > > `  
  > > `
  > > Portal: nac_transparent_auth`  
  > > `
  > > Portal is not configured yet
  > > `
* Check Point implemented the fixes for these CVEs to block any potential attack vectors.

  * Check Point is not aware of any known issue in its products related to these CVEs.

  * Check Point did not test its products for the impact that these CVEs can have.

  Because there is **no** manual mitigation for these CVEs, we recommend installing the improved software versions listed above.

  Note - Due to the nature of these CVEs, the IPS protections are not applicable against these CVEs.
* To see the current version of the Apache HTTP Server on a Security Gateway, a Management Server, a Log Server, a SmartEvent Server that runs the Gaia Operating System, run this command in the Expert mode:

  `httpd -v`

  Example output from the R82 version:

  `[Expert@R82:0]# httpd -v`  
  `
  Server version: CPWS/`2.4.61` (Unix)`  
  `
  Server built: Oct 12 2024 04:01:01`  
  `
  [Expert@R82:0]#`
* To see the current version of the Apache HTTP Server on a Quantum Spark Gateway (that runs the Gaia Embedded Operating System), run this command in the Expert mode:

  `/opt/fw1/web/Apache/apache2/bin/httpd -v`

  Example output from the R81.10.15 version:

  `[Expert@R811015]# /opt/fw1/web/Apache/apache2/bin/httpd -v`  
  `
  Server version: CPWS/`2.4.61` (Unix)`  
  `
  Server built: Aug 13 2024 13:42:11`  
  `[Expert@R811015]#`

<br />

<br />

**Revision History**  
Show / Hide revision history  

|-------------|-----------------------------------------------------------------------------------------------------------------------|
| Date        | Description                                                                                                           |
| 13 Mar 2025 | Improved the information for a Quantum Spark Gateway                                                                  |
| 30 Dec 2024 | Added the note "applies to physical servers and virtual machines" in the row with Security Gateways                   |
| 24 Dec 2024 | Added the "*mpclient list*" command to see which Software Blade web portals are currently enabled                     |
| 22 Dec 2024 | Added Quantum Spark R81.10.15 to the list of fixed versions Added the list of web portals for various Software Blades |
| 17 Dec 2024 | Added CVE-2024-39884 to the list of CVEs Added the section "Important Notes"                                          |
| 10 Dec 2024 | First release of this article                                                                                         |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
