Executive brief
IBM HTTP Server, a web server component used by WebSphere Application Server, is vulnerable to a security flaw in its Administration Server. A logged-in user with administrative privileges could exploit this issue to crash the server or access sensitive information that should otherwise be protected. This could lead to service outages or the exposure of confidential operational data.
Technical details
IBM HTTP Server 8.5 and 9.0 are vulnerable to an untrusted pointer dereference (CWE-822) within the Administration Server component. The vulnerability is accessible to an attacker who is already authenticated to the Administration Server with privileged access, typically over an adjacent network. By exploiting this flaw, the attacker can trigger an invalid pointer dereference, leading to a process crash (Denial of Service) or the unauthorized disclosure of sensitive memory contents. IBM has released interim fix PH71265 to address this issue, with permanent fixes planned for Fix Packs 8.5.5.30 and 9.0.5.29.
Affected products
- IBM HTTP Server 8.5.0.0 through 8.5.5.29, 9.0.0.0 through 9.0.5.28
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory
- 2026-05-26: patched: Interim fix PH71265 released