Impact
IBM WebSphere Application Server 8.5 and 9.0 are affected by a missing authorization check that allows a remote attacker to access sensitive information from the administrative console. The weakness is classed as CWE-862, an authorization bypass. The impact is a privilege escalation that could expose configuration details, user administrative data, and potentially other confidential information handled by the console.
Affected Systems
Vendors: IBM; product: WebSphere Application Server. Versions impacted include: 8.5.0.0 through 8.5.5.30 and 9.0.0.0 through 9.0.5.28. The affected releases are identified by the CPE strings for IBM WebSphere Application Server 8.5 and 9.0.
Risk and Exploitability
The CVSS score is 3.7, indicating a low to moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The vulnerability can be exploited remotely by executing an unauthenticated request against the administrative console, where the missing check is triggered. Because the exploitation requires only network connectivity to the console, the potential attack vector is likely remote access over standard management ports. The incomplete EPSS score and absence from KEV suggest the current risk of exploitation is low, but the presence of a remote entry point warrants timely remediation.
OpenCVE Enrichment