CVE-2026-8835
Analyzed Analyzed - Analysis Complete
IBM HTTP Server Invalid Pointer Dereference Vulnerability

Publication date: 2026-05-26

Last updated on: 2026-05-26

Assigner: IBM Corporation

Description
IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-26
Last Modified
2026-05-26
Generated
2026-06-16
AI Q&A
2026-05-26
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
ibm http_server From 8.5.0.0 (inc) to 8.5.5.30 (exc)
ibm http_server From 9.0.0.0 (inc) to 9.0.5.29 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-822 The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

IBM HTTP Server versions 8.5 and 9.0 have a vulnerability related to invalid pointer dereference. This means that a privileged user who is authenticated to the Administration Server can exploit this flaw.

Exploiting this vulnerability could allow the attacker to expose sensitive information or cause a denial of service condition.

Impact Analysis

If exploited, this vulnerability can lead to exposure of sensitive information, which could compromise confidentiality.

Additionally, it can cause a denial of service, making the IBM HTTP Server unavailable or unstable.

Compliance Impact

The vulnerability in IBM HTTP Server 8.5 and 9.0 allows a privileged, authenticated user to exploit an invalid pointer dereference, potentially exposing sensitive information or causing a denial of service.

Exposure of sensitive information could lead to non-compliance with regulations such as GDPR or HIPAA, which require protection of personal and sensitive data.

Additionally, denial of service impacts availability, which is a key aspect of many compliance frameworks that mandate system reliability and availability.

Mitigation Strategies

To mitigate the vulnerability in IBM HTTP Server 8.5 and 9.0 related to invalid pointer dereference, it is recommended to apply the appropriate interim fix or upgrade to the latest fix pack versions.

  • Apply the interim fix for APAR PH71265.
  • Upgrade to Fix Pack 9.0.5.29 or later for IBM HTTP Server version 9.0.
  • Upgrade to Fix Pack 8.5.5.30 or later for IBM HTTP Server version 8.5.
Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8835. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart