Description
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
Published: 2026-07-28
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a pre‑authentication unsafe deserialization flaw in IBM WebSphere Application Server 8.5 and 9.0 traditional. An attacker that can send crafted serialized data to the application server can bypass authentication or trigger arbitrary code execution. Based on the description, it is inferred that the flaw can be triggered from any external interface that accepts serialized payloads. The impact is a full compromise of confidentiality, integrity, and availability of the affected application servers, as exacerbated by a CVSS score of 9.8.

Affected Systems

IBM WebSphere Application Server 8.5 traditional, versions 8.5.0.0 through 8.5.5.30, and 9.0 traditional, versions 9.0.0.0 through 9.0.5.28. The affected components are all deployments of the traditional WebSphere Application Server product, as identified by the corresponding CPE strings.

Risk and Exploitability

The high CVSS score of 9.8 reflects the severity of gaining execution privileges. The EPSS score of less than 1 % indicates that the flaw is rarely exploited in the wild, but its absence from the KEV catalogue does not reduce its importance. Based on the description, it is inferred that the vulnerable endpoint is typically exposed. An attacker would simply need to send a malicious serialized object to the vulnerable endpoint. Once executed, the attacker gains the same privileges as the running application server, potentially allowing full control over the host.

Generated by OpenCVE AI on August 3, 2026 at 14:15 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH72166. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH72166 https://www.ibm.com/support/pages/node/7281092 --OR-- · Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).  For V8.5.0.0 through 8.5.5.30: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH72166 https://www.ibm.com/support/pages/node/7281092 --OR-- · Apply Fix Pack 8.5.5.31 or later (targeted availability 3Q2026).  Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Apply the interim fix for APAR PH72166 immediately from IBM support for the affected version.
  • Upgrade to Fix Pack 9.0.5.29 or later for 9.0, or 8.5.5.31 or later for 8.5, once available.
  • Restrict external access to any endpoints that accept serialized data and enforce TLS to prevent interception or manipulation.
  • Review and harden serialization handling, validating inputs and avoiding deserialization of untrusted data.

Generated by OpenCVE AI on August 3, 2026 at 14:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
Title IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-502
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T03:55:21.695Z

Reserved: 2026-07-02T19:17:20.304Z

Link: CVE-2026-14512

cve-icon Vulnrichment

Updated: 2026-07-29T12:35:07.667Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T21:17:25.783

Modified: 2026-08-05T16:24:19.383

Link: CVE-2026-14512

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:30:18Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data