PT-2025-27781 · Apache · Apache Httpd

Published

2025-07-03

·

Updated

2025-07-03

·

CVE-2025-27452

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache httpd (affected versions not specified)
Description: The configuration of the Apache httpd webserver is partly insecure due to unnecessary activated modules. These modules pose a risk to the webserver, enabling directory listing.
Recommendations: For Apache httpd, consider disabling unnecessary modules to minimize the risk of exploitation. As a temporary workaround, restrict access to the directory listing functionality until a secure configuration is implemented. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-11704
CVE-2025-27452

Affected Products

Apache Httpd