Impact
A deserialization vulnerability exists in the Name Service component of IBM WebSphere Application Server that allows an attacker to supply an attacker‑crafted serialized object. When the server processes the payload, it will deserialize the object without sufficient validation, enabling the attacker to execute arbitrary code within the server process. This compromise can affect confidentiality, integrity, and availability of applications running on the server.
Affected Systems
IBM WebSphere Application Server versions earlier than 9.0.5.29 (including every release from 9.0.0.0 through 9.0.5.28) and earlier than 8.5.5.31 (including releases from 8.5.0.0 through 8.5.5.30) are impacted. The advised resolution is to install IBM Fix Pack 9.0.5.29 SB0030823 or later for WebSphere 9.0, or Fix Pack 8.5.5.31 or later for WebSphere 8.5, both available in September 2026.
Risk and Exploitability
The CVSS score of 6.5 places this issue in the medium severity range. With no EPSS data and no presence in the CISA KEV catalog, the likelihood of public exploitation remains uncertain, yet the potential for remote code execution is significant. The likely attack path is remote, requiring an attacker to reach the Name Service interface, which may be exposed to the internet or an untrusted network. Successful exploitation would give the attacker code execution privileges under the server’s runtime context.
OpenCVE Enrichment