Description
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Immediate Patch
AI Analysis

Impact

IBM WebSphere Application Server and its Liberty profile, when bundled with IBM CICS TX Advanced, have a virtual host bypass flaw. The vulnerability arises from improper access control (CWE‑284), allowing an attacker to manipulate virtual host settings and access application resources that should be protected. Attackers could read or alter data, invoke services, or execute privileged actions within the application server scope. Confidentiality, integrity, and potentially availability of the protected services are at risk if exploited.

Affected Systems

IBM CICS TX Advanced version 10.1 running on Linux is affected. The issue manifests within the Liberty runtime incorporated in this product, impacting any virtual hosts configured on the server.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, and the EPSS score is not available, so the precise exploitation likelihood is uncertain. The vulnerability is listed as not being in CISA KEV. The likely attack vector is remote, via crafted HTTP requests that target the virtual host configuration of the WebSphere Liberty component. Even though exploitation conditions are not exhaustively described, the vulnerability could be leveraged by attackers with network access to the application server to bypass access controls and gain unauthorized privileges.

Generated by OpenCVE AI on September 19, 2026 at 10:50 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by downloading and applying the below fix. ProductVersionPlatformRemediation/FixIBM CICS TX Advanced10.1Linux Download and apply the update from  Fix Central https://www.ibm.com/support/fixcentral/quickorder


OpenCVE Recommended Actions

  • Download and apply the IBM CICS TX Advanced 10.1 fix from Fix Central (https://www.ibm.com/support/fixcentral/quickorder).
  • After installing the update, restart the CICS TX Advanced server to ensure the patch takes effect.
  • Verify that the virtual host configuration only allows authorized hosts and paths, and remove or restrict any unused virtual hosts.

Generated by OpenCVE AI on September 19, 2026 at 10:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.
Title Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.
First Time appeared Ibm
Ibm cics Tx Advanced
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:cics_tx_advanced:10.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cics_tx_advanced:10.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cics Tx Advanced
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Ibm Cics Tx Advanced
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T19:45:39.009Z

Reserved: 2026-06-08T03:27:16.708Z

Link: CVE-2026-11549

cve-icon Vulnrichment

Updated: 2026-09-18T19:45:34.492Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:00.923

Modified: 2026-09-22T19:32:25.730

Link: CVE-2026-11549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:11Z

Weaknesses