WebSphere Application Server Remote Code Execution
Published Jun 22, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.72%
Description
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.
Affected products
-
- Version 8.5StatusaffectedConstraints-
- Version 9.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | WebSphere Application Server | unaffected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM strongly recommends addressing the vulnerability now by applying a currently available Web Server Plug-ins interim fix or fix pack that contains the fix for APAR PH71376.
Web Server Plug-ins for IBM WebSphere Application Server (used with either WebSphere Application Server traditional or Liberty):
For V9.0.0.0 through 9.0.5.27: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Web Server Plug-ins Interim Fix that resolves PH71376 https://www.ibm.com/support/pages/node/7273976 --OR-- · Apply Fix Pack 9.0.5.28 or later (targeted availability 2Q2026).
For V8.5.0.0 through 8.5.5.29: · Upgrade to minimal fix pack levels as required by interim fix and then apply Web Server Plug-ins Interim Fix that resolves PH71376 https://www.ibm.com/support/pages/node/7273976 --OR-- · Apply Fix Pack 8.5.5.30 or later (targeted availability 3Q2026).
References (1)
- https://www.ibm.com/support/pages/node/7276560 vendor-advisorypatch
| Link | Providers | Tags |
|---|---|---|
| https://www.ibm.com/support/pages/node/7276560 | vendor-advisorypatch |
Change history (0)
No recorded changes yet.