Input validation error in IBM HTTP Server - CVE-2023-26281
Published: February 28, 2023
Vulnerability identifier: #VU72613
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26281
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied URL. A remote attacker can request a specially crafted URL and crash the web server.
Affected software
IBM HTTP Server
IBM Business Automation Workflow
IBM Tivoli Monitoring
IBM Business Automation Workflow
IBM Tivoli Monitoring
How to mitigate CVE-2023-26281
Install updates from vendor's website.