Description
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12278 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. |
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7231514 |
|
History
Fri, 18 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hp
Hp hp-ux Ibm aix Ibm i Ibm z\/os Linux Linux linux Kernel Microsoft Microsoft windows Oracle Oracle solaris |
|
| CPEs | cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:z\/os:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hp
Hp hp-ux Ibm aix Ibm i Ibm z\/os Linux Linux linux Kernel Microsoft Microsoft windows Oracle Oracle solaris |
Tue, 22 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Apr 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Title | IBM WebSphere Application Server server-side request forgery | |
| First Time appeared |
Ibm
Ibm websphere Application Server |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:* cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm websphere Application Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-01T00:38:55.672Z
Reserved: 2025-03-10T17:14:11.135Z
Link: CVE-2025-27907
Updated: 2025-04-22T17:33:00.257Z
Status : Analyzed
Published: 2025-04-22T17:16:45.033
Modified: 2025-07-18T15:51:47.543
Link: CVE-2025-27907
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD