vulnerability
IBM HTTP Server: CVE-2022-36760: Apache HTTP Server is vulnerable to HTTP request smuggling, caused by an inconsistent interpretation of HTTP Requests vulnerability in mod_proxy_ajp
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:C/A:N) | Feb 27, 2023 | Nov 20, 2025 | Nov 20, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:C/A:N)
Published
Feb 27, 2023
Added
Nov 20, 2025
Modified
Nov 20, 2025
Description
Apache HTTP Server is vulnerable to HTTP request smuggling, caused by an inconsistent interpretation of HTTP Requests vulnerability in mod_proxy_ajp. An attacker could exploit this vulnerability to smuggle requests to the AJP server it forwards requests to.
Solutions
ibm-http_server-apply-interim-fix-ph51982-for-9_0ibm-http_server-apply-interim-fix-ph51982-for-8_5ibm-http_server-apply-fix-pack-9_0_5_15ibm-http_server-apply-fix-pack-8_5_5_24
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.