Executive brief
IBM HTTP Server, a web server component used by WebSphere Application Server, is vulnerable to a security flaw when configured to use mutual TLS authentication. An attacker could exploit this to crash the server or execute unauthorized commands, potentially leading to a full system takeover or service disruption. Organizations using client certificate authentication should apply the available security patches immediately.
Technical details
IBM HTTP Server (versions 8.5 and 9.0) contains a code injection vulnerability (CWE-94) within its TLS mutual authentication implementation. The vulnerability is triggered when the server is configured for client certificate authentication. Although the attack complexity is rated as high, a remote attacker can potentially achieve remote code execution or cause a denial of service (DoS) without prior authentication. IBM has released interim fix PH71265 to address this issue, with permanent fixes planned for fix packs 9.0.5.29 and 8.5.5.30.
Affected products
- IBM HTTP Server 8.5.0.0 through 8.5.5.29, 9.0.0.0 through 9.0.5.28
Timeline
- 2026-05-26: disclosed: Initial publication of the security bulletin by IBM.
- 2026-05-26: patched: Interim fix PH71265 released.