Vulnerability Details
Basic Information
| Title | Security Bulletin: A security vulnerability has been identified in IBM HTTP Server shipped with IBM WebSphere Remote Server (CVE-2022-25690) |
|---|---|
| Type | ibm |
| Published | 2025-04-29T02:27:40 |
| Last Seen | 2025-04-29T11:06:00 |
| CVSS Score | 7.5 (HIGH) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | NONE |
| Availability Impact | NONE |
CVE Information
| CVE IDs | CVE-2022-25690 |
|---|---|
| CWE | |
| Bulletin Family | software |
Description
IBM HTTP Server is shipped with IBM WebSphere Remote Server. Information about a security vulnerability affecting IBM HTTP Server has been published in a security bulletin.
## Vulnerability Details
Refer to the security bulletin(s) listed in the Remediation/Fixes section
## Affected Products and Versions
**Affected Product(s)** | **Version(s)**
—|—
IBM WebSphere Remote Server | 9.0, 8.5
## Remediation/Fixes
Refer to the following security bulletins for vulnerability details and information about fixes addressed by IBM HTTP Server which is shipped with IBM WebSphere Remote Server.
**Principal Product and Version(s)** | **Affected Supporting Product and Version** | **Affected Supporting Product Security Bulletin**
—|—|—
IBM WebSphere Remote Server 9.0, 8.5 | IBM HTTP Server 9.0, 8.5 | IBM HTTP Server is vulnerable to HTTP request splitting due to the included Apache HTTP Server
## Workarounds and Mitigations
None
##
Impact Assessment
| Base Score | 7.5 |
|---|---|
| Severity | HIGH |