IBM HTTP Server 8.5, and 9.0
History

Wed, 27 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 27 May 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:http_server:8.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:9.0.0.0:*:*:*:*:*:*:*

Wed, 27 May 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-444
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to denial of service and a potential remote code execution due to improper input validation. IBM HTTP Server 8.5, and 9.0
Title IBM WebSphere Application Server and WebSphere Application Server Liberty are affected DOS and RCE. IBM HTTP Server is affected by multiple vulnerabilities
First Time appeared Ibm http Server
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:web_server_plug_ins_for_websphere_application_server_and_websphere_liberty:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:web_server_plug_ins_for_websphere_application_server_and_websphere_liberty:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm http Server
References

Tue, 26 May 2026 18:00:00 +0000

Type Values Removed Values Added
Description IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to denial of service and a potential remote code execution due to improper input validation.
Title IBM WebSphere Application Server and WebSphere Application Server Liberty are affected DOS and RCE.
First Time appeared Ibm
Ibm web Server Plug Ins For Websphere Application Server And Websphere Liberty
Weaknesses CWE-444
CPEs cpe:2.3:a:ibm:web_server_plug_ins_for_websphere_application_server_and_websphere_liberty:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:web_server_plug_ins_for_websphere_application_server_and_websphere_liberty:8.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm web Server Plug Ins For Websphere Application Server And Websphere Liberty
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-05-26T17:31:55.400Z

Updated: 2026-05-28T03:55:53.817Z

Reserved: 2026-05-21T14:32:03.337Z

Link: CVE-2026-9170

cve-icon Vulnrichment

Updated: 2026-05-27T13:58:06.591Z

cve-icon NVD

Status : Modified

Published: 2026-05-26T18:16:57.987

Modified: 2026-05-27T19:16:25.223

Link: CVE-2026-9170

cve-icon Redhat

No data.