Description
IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A deserialization vulnerability exists in the Name Service component of IBM WebSphere Application Server that allows an attacker to supply an attacker‑crafted serialized object. When the server processes the payload, it will deserialize the object without sufficient validation, enabling the attacker to execute arbitrary code within the server process. This compromise can affect confidentiality, integrity, and availability of applications running on the server.

Affected Systems

IBM WebSphere Application Server versions earlier than 9.0.5.29 (including every release from 9.0.0.0 through 9.0.5.28) and earlier than 8.5.5.31 (including releases from 8.5.0.0 through 8.5.5.30) are impacted. The advised resolution is to install IBM Fix Pack 9.0.5.29 SB0030823 or later for WebSphere 9.0, or Fix Pack 8.5.5.31 or later for WebSphere 8.5, both available in September 2026.

Risk and Exploitability

The CVSS score of 6.5 places this issue in the medium severity range. With no EPSS data and no presence in the CISA KEV catalog, the likelihood of public exploitation remains uncertain, yet the potential for remote code execution is significant. The likely attack path is remote, requiring an attacker to reach the Name Service interface, which may be exposed to the internet or an untrusted network. Successful exploitation would give the attacker code execution privileges under the server’s runtime context.

Generated by OpenCVE AI on September 19, 2026 at 12:21 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply IBM’s Fix Pack 9.0.5.29 SB0030823 or later for WebSphere 9.0, or 8.5.5.31 or later for WebSphere 8.5, following the vendor’s official advisory.
  • Restrict network access to the Name Service component so that only trusted hosts or isolated networks can communicate with it, limiting the attack surface.
  • Implement strict deserialization controls: validate incoming serialized data, allow only trusted classes, and follow best practices for mitigating deserialization flaws in line with CWE‑502.

Generated by OpenCVE AI on September 19, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-502
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:42.354Z

Reserved: 2026-06-09T00:03:47.477Z

Link: CVE-2026-11711

cve-icon Vulnrichment

Updated: 2026-09-19T14:09:00.342Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:01.280

Modified: 2026-09-22T19:32:25.730

Link: CVE-2026-11711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:11Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data