Where
-Infinity
0
Severity
9.8
EPSS
0.49%
Code Injection, Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

First published (updated )
Severity
7.3
EPSS
0.25%
AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.

First published (updated )
Severity
8
EPSS
0.26%
Buffer Overflow
AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service.

First published (updated )
Severity
9.8
EPSS
0.46%
Code Injection
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).

First published (updated )
Severity
7.5
EPSS
0.36%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module modmemcache.

First published (updated )
Severity
9.1
EPSS
0.20%
AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.

First published (updated )
Severity
7.5
EPSS
0.20%
AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module modfastcgi module.

First published (updated )
Severity
7.5
EPSS
0.38%
Null Pointer Dereference
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module modibmupload.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 255828.

1 / 4
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

IBM GSKit information disclosure

1 / 2
First published (updated )
First published (updated )
Advisory
IBM-6958522
Severity
7.5
Input Validation
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. IBM X-Force ID: 248296.

1 / 3
Source: MITRE
First published (updated )
Severity
9
Buffer Overflow
AV:N/AC:L/Au:S/C:C/I:C/A:C

Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.

First published (updated )
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown vectors.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to inject arbitrary web script or HTML via vectors involving unspecified documentation files in (1) manual/ibm/ and (2) htdocs//manual/ibm/.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

PHP 4.3.4 and earlier in Apache 1.x and 2.x (modphp) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.

First published (updated )
Severity
6.4
Buffer Overflow
AV:N/AC:L/Au:N/C:N/I:P/A:P

The apgetmimeheaderscore function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.

First published (updated )
Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

Heap-based buffer overflow in proxyutil.c for modproxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

First published (updated )
Severity
7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P

moddigestapple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP).

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.

First published (updated )
Severity
7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P

IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203