Description
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
Published: 2026-07-28
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM WebSphere Application Server 9.0.0 and 8.5.0 can be exploited by a remote attacker through an unsafe deserialization process that allows the attacker to read sensitive information from the system. The flaw is a classic case of exposed sensitive data to an unauthorized actor (CWE-532). The description does not explicitly state whether authentication is required, so it is unclear if the vulnerability can be exploited without credentials.

Affected Systems

The vulnerability affects IBM WebSphere Application Server versions 8.5.0.0 through 8.5.5.30 and 9.0.0.0 through 9.0.5.28. Upgrading to at least fix pack 8.5.5.31 or 9.0.5.29—or applying the interim fix PH72166—removes the exposed deserialization code and stops the information leak.

Risk and Exploitability

The CVSS score of 7.4 demonstrates a high impact to confidentiality. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The likely attack vector is a remote attacker sending a crafted serialized object to a vulnerable component; the description does not explicitly state the exact component, but unsafe deserialization patterns strongly imply exploitation of a deserialization routine exposed to network traffic.

Generated by OpenCVE AI on August 3, 2026 at 14:16 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH72166. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH72166 https://www.ibm.com/support/pages/node/7281092 --OR-- · Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).  For V8.5.0.0 through 8.5.5.30: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH72166 https://www.ibm.com/support/pages/node/7281092 --OR-- · Apply Fix Pack 8.5.5.31 or later (targeted availability 3Q2026).  Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Install the interim fix PH72166 from the IBM Support Center
  • If an interim fix is not available, upgrade to the latest available fix pack—9.0.5.29 or later for 9.0, or 8.5.5.31 or later for 8.5
  • Review the application server’s serialization configuration and disable or restrict unsafe deserialization, following IBM security best practices

Generated by OpenCVE AI on August 3, 2026 at 14:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
Title IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-532
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T03:55:23.956Z

Reserved: 2026-07-02T20:20:14.675Z

Link: CVE-2026-14528

cve-icon Vulnrichment

Updated: 2026-07-29T19:24:12.725Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T21:17:26.060

Modified: 2026-08-05T16:00:48.987

Link: CVE-2026-14528

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:30:18Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File