Ibm Http Server vulnerabilities
21 known vulnerabilities affecting ibm/http_server.
Total CVEs
21
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH9MEDIUM6
Vulnerabilities
Page 1 of 2
CVE-2026-8855CRITICALCVSS 9.8≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-05-26
CVE-2026-8855 [CRITICAL] CWE-94 CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configu
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
nvd
CVE-2026-8856CRITICALCVSS 9.1≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-05-26
CVE-2026-8856 [CRITICAL] CWE-400 CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
nvd
CVE-2026-8834HIGHCVSS 8.0≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-05-26
CVE-2026-8834 [HIGH] CWE-122 CVE-2026-8834: IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authentica
IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service.
nvd
CVE-2026-8854HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-05-26
CVE-2026-8854 [HIGH] CWE-825 CVE-2026-8854: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cach
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.
nvd
CVE-2026-8850HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-05-26
CVE-2026-8850 [HIGH] CWE-476 CVE-2026-8850: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_uplo
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.
nvd
CVE-2026-8835HIGHCVSS 7.3≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-05-26
CVE-2026-8835 [HIGH] CWE-822 CVE-2026-8835: IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authen
IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.
nvd
CVE-2026-8852HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-05-26
CVE-2026-8852 [HIGH] CWE-617 CVE-2026-8852: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.
nvd
CVE-2023-32342HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.24≥ 9.0.0.0, < 9.0.5.162023-05-30
CVE-2023-32342 [HIGH] CWE-203 CVE-2023-32342: IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based si
IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 255828.
nvd
CVE-2023-26281HIGHCVSS 7.5v8.5.0.0v8.52023-03-01
CVE-2023-26281 [HIGH] CWE-20 CVE-2023-26281: IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a de
IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. IBM X-Force ID: 248296.
nvd
CVE-2015-4947CRITICALCVSS 9.0≥ 6.1.0.0, ≤ 6.1.0.47≥ 7.0.0.0, < 7.0.0.39+2 more2015-09-15
CVE-2015-4947 [CRITICAL] CWE-119 CVE-2015-4947: Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47
Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-5955CRITICALCVSS 10.0v5.32012-12-20
CVE-2012-5955 [CRITICAL] CVE-2012-5955: Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (
Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown vectors.
nvd
CVE-2011-1360MEDIUMCVSS 4.3≤ 2.0.47v1.0+18 more2011-10-28
CVE-2011-1360 [MEDIUM] CWE-79 CVE-2011-1360: Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used i
Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to inject arbitrary web script or HTML via vectors involving unspecified documentation files in (1) manual/ibm/ and (2) htdocs/*/manual/ibm/.
nvd
CVE-2010-0425CRITICALCVSS 10.0PoCv6.0.2v6.0.2.1+33 more2010-03-05
CVE-2010-0425 [CRITICAL] CVE-2010-0425: modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 t
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related t
nvd
CVE-2004-0263MEDIUMCVSS 5.0v1.3.192004-11-23
CVE-2004-0263 [MEDIUM] CVE-2004-0263: PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual host
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
nvd
CVE-2004-0492CRITICALCVSS 10.0v1.3.26v1.3.26.1+2 more2004-08-06
CVE-2004-0492 [CRITICAL] CVE-2004-0492: Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote at
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
nvd
CVE-2004-0493MEDIUMCVSS 6.4PoCv2.0.42v2.0.42.1+3 more2004-08-06
CVE-2004-0493 [MEDIUM] CVE-2004-0493: The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a deni
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
nvd
CVE-2004-1082HIGHCVSS 7.5v1.3.192004-02-03
CVE-2004-1082 [HIGH] CVE-2004-1082: mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
nvd
CVE-2002-1822MEDIUMCVSS 5.0v1.02002-12-31
CVE-2002-1822 [MEDIUM] CVE-2002-1822: IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory a
IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP).
nvd
CVE-2001-0122MEDIUMCVSS 5.0PoCv1.3.12.22001-03-13
CVE-2001-0122 [MEDIUM] CVE-2001-0122: Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
nvd
CVE-2000-1168HIGHCVSS 7.5v1.3.6.32001-01-09
CVE-2000-1168 [HIGH] CVE-2000-1168: IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and pos
IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
nvd
1 / 2Next →