← Vulnerability feed

Vulnerability record · CVE-2015-4947 · published 15 September 2015

CVE-2015-4947: Ibm http server memory buffer overflow vulnerability

Ibm · Http Server

Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.

9.0 CVSS 2.0 High EPSS 7.9% · top 5.5% CWE-119 · Memory buffer overflow
9.0CVSS 2.0 base score
7.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-4947 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-5955Ibm http server vulnerabilityUnspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute …EPSS 4.4%10.0CVE-2010-0425Apache mod_isapi on Windows remote code execution via orphaned callbacksmod_isapi in Apache HTTP Server on Windows does not ensure request processing is complete before calling isapi_unload for an ISAPI .dll module, leavi…EPSS 94%analysed10.0CVE-2004-0492Apache http server vulnerabilityHeap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process cra…EPSS 34%9.8CVE-2026-8855Ibm http server code injection vulnerabilityIBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au…EPSS 0.85%9.8CVE-2026-9170Ibm http server code injection vulnerabilityIBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.EPSS 0.86%9.1CVE-2026-8856Ibm http server uncontrolled resource consumption vulnerabilityIBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configura…EPSS 0.34%8.0CVE-2026-8834Ibm http server heap-based buffer overflow vulnerabilityIBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit t…EPSS 0.34%7.5CVE-2026-8854Ibm http server vulnerabilityIBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.EPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2015-4947), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.