Executive brief
IBM HTTP Server, a web server component used by WebSphere Application Server, is vulnerable to a denial of service attack. An attacker with local access to the server's configuration files can consume excessive system resources, potentially causing the web server to crash or become unresponsive. This could lead to service outages for applications relying on the server for web traffic.
Technical details
IBM HTTP Server is vulnerable to uncontrolled resource consumption (CWE-400) within its configuration handling. The vulnerability is triggered in specific configurations where an attacker has local write access to parts of the server configuration. By manipulating these configuration files, an attacker can cause a denial of service condition. The attack vector is local (AV:L), meaning the attacker must already have a foothold on the system to modify the configuration. IBM has released interim fix PH71265 to address this issue, with permanent fixes planned for Fix Packs 8.5.5.30 and 9.0.5.29.
Affected products
- IBM HTTP Server 8.5.0.0 through 8.5.5.29, 9.0.0.0 through 9.0.5.28
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory
- 2026-05-26: patched: Interim fix PH71265 released