IBM HTTP Server is affected by multiple vulnerabilities
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 0.5%
exploitation probability
0.5%top 63% of all CVEs
observed exploitation
nono source reports it
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
IBM · HTTP Server