IBM WebSphere Application Server Liberty Server-Side Request Forgery
Published Mar 25, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.29%
Description
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Affected products
-
- Version 17.0.0.3StatusaffectedConstraints<=26.0.0.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| IBM | WebSphere Application Server Liberty | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Remediation/Fixes IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH70017 . To determine if a feature is enabled for IBM WebSphere Application Server Liberty, refer to How to determine if Liberty is using a specific feature . For IBM WebSphere Application Server Liberty 17.0.0.3 - 26.0.0.3 using the samlWeb-2.0 feature: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH70017 --OR-- · Apply Liberty Fix Pack 26.0.0.4 or later (targeted availability 2Q2026). Additional interim fixes may be available and linked off the interim fix download page.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-15982 Advisory
- https://www.ibm.com/support/pages/node/7267347 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-15982 | Advisory | |
| https://www.ibm.com/support/pages/node/7267347 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.