Known vulnerabilities in IBM HTTP Server - page 3

Software CPE: cpe:2.3:a:ibm_corporation:ibm_http_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 58
Public exploits: 9
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM HTTP Server IBM HTTP Server is affected by 58 known vulnerabilities: 1 critical, 10 high, 36 medium, 11 low Critical High Medium Low

Vulnerabilities (58)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU71754 - Integer overflow
CVE-2022-25147
CWE-190 High
No
No
8.5.5.24, 9.0.5.15 02.02.2023 SB2023020210
SB2023020212
SB2023020942
and 47 more
#VU68718 - Use After Free
CVE-2022-43680
CWE-416 Medium
No
No
7.0.0.45 Interim Fix PH50316, 8.0.0.15 Interim Fix PH50316, 8.5.5.23, 9.0.5.15 25.10.2022 SB2022102560
SB2022102566
SB2022103010
and 97 more
#VU67532 - Use After Free
CVE-2022-40674
CWE-416 High
No
No
- 21.09.2022 SB2022092118
SB2022092119
SB2022092317
and 111 more
#VU64089 - Improper Authentication
CVE-2022-31813
CWE-287 Medium
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 49 more
#VU64088 - Out-of-bounds read
CVE-2022-30556
CWE-125 Medium
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 31 more
#VU64085 - Improper input validation
CVE-2022-29404
CWE-20 Medium
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 30 more
#VU64083 - Out-of-bounds read
CVE-2022-28615
CWE-125 Low
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 41 more
#VU64081 - Out-of-bounds read
CVE-2022-28614
CWE-125 Low
No
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 36 more
#VU64078 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-26377
CWE-444 Medium
Available
No
- 08.06.2022 SB2022060817
SB2022060901
SB2022061611
and 39 more
#VU60739 - Integer overflow
CVE-2022-25315
CWE-190 High
No
No
- 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 99 more
#VU60737 - Stack-based buffer overflow
CVE-2022-25313
CWE-121 High
No
No
- 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 64 more
#VU60736 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-25235
CWE-94 High
No
No
- 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 106 more
#VU60733 - Improper input validation
CVE-2022-25236
CWE-20 Medium
No
No
- 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 109 more
#VU56681 - NULL Pointer Dereference
CVE-2021-34798
CWE-476 Medium
No
No
9.0.5.10 17.09.2021 SB2021091706
SB2021091707
SB2021092301
and 44 more
#VU56679 - Memory corruption
CVE-2021-39275
CWE-119 Medium
No
No
7.0.0.45, 8.0.0.15, 8.5.5.21, 9.0.5.10 17.09.2021 SB2021091706
SB2021091707
SB2021092301
and 44 more
#VU56678 - Server-Side Request Forgery (SSRF)
CVE-2021-40438
CWE-918 High
Available
Exploited
9.0.5.10 17.09.2021 SB2021091706
SB2021091707
SB2021092301
and 42 more
#VU7242 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2017-9233
CWE-611 Low
No
No
7.0.0.45 Interim Fix PH50316, 8.0.0.15 Interim Fix PH50316, 8.5.5.23, 9.0.5.15 25.06.2017 SB2017062501
SB2017062610
SB2017062502
and 16 more
#VU42119 - Resource exhaustion
CVE-2013-0340
CWE-400 Medium
No
No
7.0.0.45 Interim Fix PH50316, 8.0.0.15 Interim Fix PH50316, 8.5.5.23, 9.0.5.15 21.01.2014 SB2014012103
SB2017011129
SB2021052301
and 16 more


Showing elements 41 - 60 out of 58