VendorsIBMhttp_serverany version
Vulnerabilities

IBM HTTP Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-8855
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
9.8EPSS 0.008
CVE-2026-8856
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
9.1EPSS 0.003
CVE-2015-4947
Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.
Published 2015-09-15 · Modified
9.0EPSS 0.079
CVE-2026-8834
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
8.0EPSS 0.003
CVE-2023-32342
IBM GSKit information disclosure
Published 2023-05-30 · Modified
7.5EPSS 0.009
CVE-2026-8850
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
7.5EPSS 0.005
CVE-2026-8854
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
7.5EPSS 0.005
CVE-2026-8852
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
7.5EPSS 0.003
CVE-2026-8835
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
7.3EPSS 0.003
CVE-2011-1360
Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to inject arbitrary web script or HTML via vectors involving unspecified documentation files in (1) manual/ibm/ and (2) htdocs/*/manual/ibm/.
Published 2011-10-28 · Modified
4.3EPSS 0.017