Known vulnerabilities in IBM HTTP Server - page 3
Vendor:
IBM Corporation
Software:
IBM HTTP Server
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_http_server:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
58
Public exploits:
9
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
9.0.5.26
8.5.5.25
8.5.5.28
9.0.5.28
8.5.5.30
9.0.5.27
9.0.5.14
9.0.5.24
9.0.5.23
9.0.5.22
9.0.5.25
8.5.5.29
8.5.5.27
9.0.5.21
9.0.5.20
8.5.5.26
9.0.5.19
9.0.5.17
9.0.5.18
9.0.5.16
8.5.5.24
7.0.0.45 Interim Fix PH50316
8.0.0.15 Interim Fix PH50316
8.5.5.23
9.0.5.15
7.0.0.44
7.0.0.43
7.0.0.42
7.0.0.41
7.0.0.40
7.0.0.39
7.0.0.38
7.0.0.37
7.0.0.36
7.0.0.35
7.0.0.34
7.0.0.33
7.0.0.32
7.0.0.31
7.0.0.30
7.0.0.29
7.0.0.28
7.0.0.27
7.0.0.26
7.0.0.25
7.0.0.24
7.0.0.23
7.0.0.22
7.0.0.21
7.0.0.20
7.0.0.19
7.0.0.18
7.0.0.17
7.0.0.16
7.0.0.15
7.0.0.14
7.0.0.13
7.0.0.12
7.0.0.11
7.0.0.10
7.0.0.9
7.0.0.8
7.0.0.7
7.0.0.6
7.0.0.5
7.0.0.4
7.0.0.3
7.0.0.2
7.0.0.1
7.0.0.0
8.0.0.14
8.0.0.13
8.0.0.12
8.0.0.11
8.0.0.10
8.0.0.9
8.0.0.8
8.0.0.7
8.0.0.6
8.0.0.5
8.0.0.4
8.0.0.3
8.0.0.2
8.0.0.1
8.0.0.0
8.5.5.22
8.5.5.20
8.5.5.19
8.5.5.18
8.5.5.17
8.5.5.16
8.5.5.15
8.5.5.14
8.5.5.13
8.5.5.12
8.5.5.11
8.5.5.10
8.5.5.9
8.5.5.8
8.5.5.7
8.5.5.6
8.5.5.5
8.5.5.4
8.5.5.3
8.5.5.2
8.5.5.1
8.5.5.0
9.0.5.0
9.0.5.13
9.0.5.12
9.0.5.11
9.0.5.9
9.0.5.8
9.0.5.7
9.0.5.6
9.0.5.5
9.0.5.4
9.0.5.3
9.0.5.2
9.0.5.1
7.0.0.45
8.0.0.15
8.5.5.21
9.0.5.10
9.0.0.0
8.5.0.0
8.0
7.0
Vulnerabilities (58)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU71754 - Integer overflow CVE-2022-25147 |
CWE-190 | High | 8.5.5.24, 9.0.5.15 | 02.02.2023 |
SB2023020210 SB2023020212 SB2023020942 and 47 more |
||
| #VU68718 - Use After Free CVE-2022-43680 |
CWE-416 | Medium | 7.0.0.45 Interim Fix PH50316, 8.0.0.15 Interim Fix PH50316, 8.5.5.23, 9.0.5.15 | 25.10.2022 |
SB2022102560 SB2022102566 SB2022103010 and 97 more |
||
| #VU67532 - Use After Free CVE-2022-40674 |
CWE-416 | High | - | 21.09.2022 |
SB2022092118 SB2022092119 SB2022092317 and 111 more |
||
| #VU64089 - Improper Authentication CVE-2022-31813 |
CWE-287 | Medium | - | 08.06.2022 |
SB2022060817 SB2022060901 SB2022061611 and 49 more |
||
| #VU64088 - Out-of-bounds read CVE-2022-30556 |
CWE-125 | Medium | - | 08.06.2022 |
SB2022060817 SB2022060901 SB2022061611 and 31 more |
||
| #VU64085 - Improper input validation CVE-2022-29404 |
CWE-20 | Medium | - | 08.06.2022 |
SB2022060817 SB2022060901 SB2022061611 and 30 more |
||
| #VU64083 - Out-of-bounds read CVE-2022-28615 |
CWE-125 | Low | - | 08.06.2022 |
SB2022060817 SB2022060901 SB2022061611 and 41 more |
||
| #VU64081 - Out-of-bounds read CVE-2022-28614 |
CWE-125 | Low | - | 08.06.2022 |
SB2022060817 SB2022060901 SB2022061611 and 36 more |
||
| #VU64078 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-26377 |
CWE-444 | Medium | - | 08.06.2022 |
SB2022060817 SB2022060901 SB2022061611 and 39 more |
||
| #VU60739 - Integer overflow CVE-2022-25315 |
CWE-190 | High | - | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 99 more |
||
| #VU60737 - Stack-based buffer overflow CVE-2022-25313 |
CWE-121 | High | - | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 64 more |
||
| #VU60736 - Improper Control of Generation of Code ('Code Injection') CVE-2022-25235 |
CWE-94 | High | - | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 106 more |
||
| #VU60733 - Improper input validation CVE-2022-25236 |
CWE-20 | Medium | - | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 109 more |
||
| #VU56681 - NULL Pointer Dereference CVE-2021-34798 |
CWE-476 | Medium | 9.0.5.10 | 17.09.2021 |
SB2021091706 SB2021091707 SB2021092301 and 44 more |
||
| #VU56679 - Memory corruption CVE-2021-39275 |
CWE-119 | Medium | 7.0.0.45, 8.0.0.15, 8.5.5.21, 9.0.5.10 | 17.09.2021 |
SB2021091706 SB2021091707 SB2021092301 and 44 more |
||
| #VU56678 - Server-Side Request Forgery (SSRF) CVE-2021-40438 |
CWE-918 | High | 9.0.5.10 | 17.09.2021 |
SB2021091706 SB2021091707 SB2021092301 and 42 more |
||
| #VU7242 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2017-9233 |
CWE-611 | Low | 7.0.0.45 Interim Fix PH50316, 8.0.0.15 Interim Fix PH50316, 8.5.5.23, 9.0.5.15 | 25.06.2017 |
SB2017062501 SB2017062610 SB2017062502 and 16 more |
||
| #VU42119 - Resource exhaustion CVE-2013-0340 |
CWE-400 | Medium | 7.0.0.45 Interim Fix PH50316, 8.0.0.15 Interim Fix PH50316, 8.5.5.23, 9.0.5.15 | 21.01.2014 |
SB2014012103 SB2017011129 SB2021052301 and 16 more |
Showing elements 41 - 60 out of 58