Authors: Created by IBM


IBM HTTP Server used by IBM WebSphere Application Server is affected by multiple vulnerabilities due to libexpat and the included Apache HTTP Server. CVEID:  CVE-2025-66200[1]
DESCRIPTION:  mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server.Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.This issue affects Apache HTTP Server:from 2.4.7 through...

Just published by IBM: Read more