Description
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote information disclosure via FileTransfer servlet
Action: Patch
AI Analysis

Impact

The vulnerability, identified as CWE-650, allows a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. This information disclosure can expose directory structures, file names, and other metadata that might aid in subsequent attacks, compromising confidentiality.

Affected Systems

IBM WebSphere Application Server versions 8.5.0 through 8.5.5.30 and 9.0.0 through 9.0.5.28 are affected. The recommended fix is to apply Fix Pack 9.0.5.29 SB0030823 or a later pack for WebSphere 9, and to apply Pack 8.5.5.31 or a later pack for WebSphere 8.5.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. The EPSS score of <1% signifies a low exploitation probability. Although it is not currently listed in the CISA KEV, the vulnerability can still be leveraged remotely if the FileTransfer servlet is exposed, allowing attackers to gather file system metadata that could aid in further attacks.

Generated by OpenCVE AI on September 19, 2026 at 17:53 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Determine the exact WebSphere Application Server version and environment in use
  • Download the appropriate IBM fix pack from the IBM support website (9.0.5.29 SB0030823 or later for v9, 8.5.5.31 or later for v8.5)
  • Apply the fix pack following IBM’s documented installation procedures
  • Test the application for functional integrity after patching to ensure no regression occurs

Generated by OpenCVE AI on September 19, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-650
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:43.715Z

Reserved: 2026-06-08T02:35:35.322Z

Link: CVE-2026-11537

cve-icon Vulnrichment

Updated: 2026-09-19T14:10:50.039Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:05.893

Modified: 2026-09-19T15:16:56.780

Link: CVE-2026-11537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:00:13Z

Weaknesses
  • CWE-650

    Trusting HTTP Permission Methods on the Server Side