[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in Apache HTTP Server ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, und um Dateien zu manipulieren.
CSIRTS triage
- What
- Multiple vulnerabilities can be exploited by an attacker to carry out a Denial of Service attack, bypass security measures, disclose information, and manipulate files.
- Who is affected
- Deployments of Apache HTTP Server are affected.
- Urgency
- Remediation is high urgency due to the potential for severe impacts.
- Action
- Update to the latest version of Apache HTTP Server.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Apache HTTP Server
Get an email when a new Apache HTTP Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1529
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2023-387093.9% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 90% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-425160.74% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-432040.81% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2024-433941.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 65% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-472520.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2025-230481.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2025-496301.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 66% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-498120.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2025-530204.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 91% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2023-38709 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-42516 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-43204 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-43394 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-47252 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-23048 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-49630 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-49812 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-53020 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Apache HTTP Server: Mehrere Schwachstellen ermöglichen Manipulation von Datencert-bund
- criticalexploited[UPDATE] [critical] Oracle Fusion Middleware: Multiple Vulnerabilitiescert-bund
Recent advisories for Apache HTTP Server
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellencert-bund · 2026-09-11
- high[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellencert-bund · 2026-09-11
- high[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellencert-bund · 2026-09-11
- highexploited[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellencert-bund · 2026-09-11
- medium[UPDATE] [mittel] Apache HTTP Server: Mehrere Schwachstellen ermöglichen Manipulation von Datencert-bund · 2026-09-11
- medium[UPDATE] [mittel] Apache HTTP Server: Mehrere Schwachstellen ermöglichen Denial of Servicecert-bund · 2026-09-11
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-11
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen2026-09-11