CVE-2023-26281: IBM HTTP Server denial of service
Published Feb 27, 2023
·Updated
IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. IBM X-Force ID: 248296.
Other sources
IBM HTTP Server used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL.
Affected Software
8 affected components
IBM HTTP Server<=8.5
IBM HTTP Server=8.5.0.0
HP HP-UX
IBM AIX
IBM Z\/os
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Remediation
Patch Available
Event History
Feb 27, 2023
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Feb 28, 2023
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this IBM HTTP Server vulnerability?
The vulnerability ID is CVE-2023-26281.
2
What is the severity of CVE-2023-26281?
The severity of CVE-2023-26281 is high, with a score of 7.5.
3
How can a remote user exploit CVE-2023-26281?
A remote user can exploit CVE-2023-26281 by sending a specially crafted URL to the affected IBM HTTP Server.
4
Which versions of IBM HTTP Server are affected by CVE-2023-26281?
IBM HTTP Server version 8.5.0.0 is affected by CVE-2023-26281.
5
Is IBM WebSphere Application Server affected by CVE-2023-26281?
No, IBM WebSphere Application Server is not affected by CVE-2023-26281.