CVE-2026-8835: IBM HTTP Server is affected by multiple vulnerabilities
IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71265 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.5.5.30 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.5.29
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8835?
The severity of CVE-2026-8835 is classified as high with a score of 7.3.
How do I fix CVE-2026-8835?
To fix CVE-2026-8835, apply the currently available interim fix or fix pack that addresses APAR PH71265.
What products are affected by CVE-2026-8835?
CVE-2026-8835 affects IBM HTTP Server versions 8.5 and 9.0.
What types of vulnerabilities does CVE-2026-8835 include?
CVE-2026-8835 includes vulnerabilities such as invalid pointer dereference that can lead to sensitive information exposure or denial of service.
Who is at risk due to CVE-2026-8835?
Privileged users authenticated to the Administration Server are at risk of exploiting CVE-2026-8835.