PT-2025-26677 · Apache · Apache Http Server

Chua Wei Xun

·

Published

2025-06-23

·

Updated

2025-06-24

·

CVE-2025-48463

CVSS v3.1

3.1

Low

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache HTTP versions (affected versions not specified)
Description: The issue arises from the use of unencrypted HTTP communication, allowing an attacker to intercept data and conduct session hijacking on exposed data. This could lead to unauthorized access or data tampering.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-08189
CVE-2025-48463

Affected Products

Apache Http Server