IBM HTTP Server Remote Code Execution and Denial-of-Service Vulnerability in TLS Mutual Authentication Configurations

Vulnerability

A vulnerability in IBM HTTP Server versions 8.5 and 9.0 allows for remote code execution and denial-of-service conditions, specifically in configurations that utilize TLS mutual authentication (client authentication).

Impact

Exploitation of this vulnerability could lead to unauthorized remote code execution on the server or cause a denial-of-service condition, disrupting normal server operations.

Remediation

Users are advised to upgrade to IBM HTTP Server Fix Pack 9.0.5.29 or later, or Fix Pack 8.5.5.30 or later. For both versions, additional interim fixes may be available and linked off the interim fix download page.

Added: May 26, 2026, 10:24 PM
Updated: May 26, 2026, 10:24 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
7.5
exploitability
7.0
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.