vulnerability

IBM HTTP Server: CVE-2014-8730: IBM HTTP Server could allow a remote attacker to obtain sensitive information, caused by the failure to check the contents of the padding bytes when using CBC cipher suites of some TLS implementations

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
Sep 7, 2022
Added
Sep 7, 2022
Modified
Nov 20, 2025

Description

IBM HTTP Server could allow a remote attacker to obtain sensitive information, caused by the failure to check the contents of the padding bytes when using CBC cipher suites of some TLS implementations. A remote user with the ability to conduct a man-in-the-middle attack could exploit this vulnerability via a POODLE (Padding Oracle On Downgraded Legacy Encryption) like attack to decrypt sensitive information and calculate the plain text of secure connections.

Solutions

ibm-http_server-apply-interim-fix-pi31516-for-8_5ibm-http_server-apply-interim-fix-pi31516-for-8_0ibm-http_server-apply-interim-fix-pi31516-for-7_0ibm-http_server-apply-interim-fix-pi31516-for-6_1ibm-http_server-apply-interim-fix-pi31516-for-6_0ibm-http_server-apply-fix-pack-8_5_5_5ibm-http_server-apply-fix-pack-8_0_0_11ibm-http_server-apply-fix-pack-7_0_0_37ibm-http_server-apply-fix-pack-6_1_0_48ibm-http_server-apply-fix-pack-6_0_2_44
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.