Impact
The vulnerability is an authentication bypass in the SOAP/JMX connector of IBM WebSphere Application Server. An attacker who can reach the SOAP endpoint can issue JMX management commands without providing valid credentials, which may allow the attacker to read or modify management data, execute arbitrary code, or exfiltrate sensitive information. The weakness is a classic example of a missing or improperly implemented authentication control (CWE‑306), implying potential compromise of confidentiality, integrity, and availability of the application server and its hosted applications.
Affected Systems
IBM WebSphere Application Server 8.5.x versions prior to 8.5.5.31 and 9.0.x versions prior to 9.0.5.29 are affected. These versions expose the SOAP/JMX connector without proper authentication enforcement.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate risk. No EPSS value is supplied, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that there are no documented active exploitations to date. Attackers would need network access to the SOAP/JMX interface; with this access, they can bypass authentication and potentially gain privileged operations. While the impact is moderate, the ease of exploitation via network protocols makes patching advisable.
OpenCVE Enrichment