IBM HTTP Server
cpe:2.3:a:ibm:http_server:*:*:*:*:*:*:*
- 8.5
- 9.0
A vulnerability in IBM HTTP Server versions 8.5 and 9.0 allows for remote code execution and denial-of-service conditions, specifically in configurations that utilize TLS mutual authentication (client authentication).
Exploitation of this vulnerability could lead to unauthorized remote code execution on the server or cause a denial-of-service condition, disrupting normal server operations.
Users are advised to upgrade to IBM HTTP Server Fix Pack 9.0.5.29 or later, or Fix Pack 8.5.5.30 or later. For both versions, additional interim fixes may be available and linked off the interim fix download page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.