Impact of Apache HTTP Server vulnerabilities CVE-2026-4235 and CVE-2026-34355 on Common Services
search cancel

Impact of Apache HTTP Server vulnerabilities CVE-2026-4235 and CVE-2026-34355 on Common Services

book

Article ID: 445063

calendar_today

Updated On:

Products

Common Components and Services for z/OS

Issue/Introduction

This article addresses inquiries regarding the potential impact of Apache HTTP Server security vulnerabilities CVE-2026-4235 and CVE-2026-34355 on the Common Components and Services for z/OS (CCS) environment. It clarifies why these vulnerabilities do not affect the CCS (aka CA90s) product suite.

Environment

Product: Common Components and Services for z/OS
Component: CCS Tomcat

Cause

These vulnerabilities specifically target the Apache HTTP Server (`httpd`) and its associated modules (`mod_dav_fs` and `mod_proxy_html`).

Resolution

You do not need to take any action for Common Components and Services for z/OS (CCS) regarding these CVEs.

  • While CCS delivers a component named CCS Tomcat, it is distinct from the Apache HTTP Server (`httpd`).
  • CCS does not utilize the Apache HTTP Server or the specific modules (`mod_dav_fs` and `mod_proxy_html`) mentioned in the security advisories.
  • Since the vulnerable software is not present within the CCS (CA90s) environment, the product is not susceptible to these exploits.

Additional Information

For more information on Broadcom's response to security vulnerabilities, please refer to the Broadcom Security Advisory page.

If you require further assistance or wish to speak with a customer representative, see Contact Support. Scroll to the bottom of the page and click on your respective region.