Description
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
Published: 2026-07-29
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM WebSphere Application Server 9.0, 8.5 and the WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 suffer a server‑side request forgery flaw when the sipServlet‑1.1 feature is enabled. The vulnerability comes from missing authentication checks (CWE‑306) that allow an attacker to craft SIP requests that the server forwards to internal or external resources. If successfully exploited, the attacker could access sensitive internal systems, exfiltrate data or reach protected services. The flaw may also serve as a stepping‑stone for further attacks within the internal network.

Affected Systems

Affected systems include IBM WebSphere Application Server 9.0, IBM WebSphere Application Server 8.5, and IBM WebSphere Application Server Liberty from version 17.0.0.3 up to 26.0.0.8. The flaw only applies when the sipServlet‑1.1 feature is enabled. Exact impacted version ranges are 9.0.0.0‑9.0.5.28 for traditional servers, 8.5.0.0‑8.5.5.30 for older traditional servers, and Liberty 17.0.0.3‑26.0.0.8.

Risk and Exploitability

The CVSS score of 9.4 classifies this flaw as critical, with an EPSS score of less than 1% indicating a low probability of widespread exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, but its high severity and potential to expose internal resources make it a priority. Attackers would need to reach the vulnerable server and supply a crafted SIP request; the missing authentication check allows the server to forward the request to arbitrary hosts. If the target host performs actions that impact the server’s state, the attacker could potentially expand the attack surface within the internal network.

Generated by OpenCVE AI on August 2, 2026 at 07:45 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH72053 or DT495928. To determine if a feature is enabled for WebSphere Application Server Liberty, refer to  How to determine if Liberty is using a specific feature https://www.ibm.com/support/pages/node/6553910 .  For IBM WebSphere Application Server Liberty 17.0.0.3 - 26.0.0.8 using the sipServlet-1.1 feature: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH72053 https://www.ibm.com/support/pages/node/7281718 --OR-- · Apply Fix Pack 26.0.0.9 or later (targeted availability 3Q2026). For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT495928 https://www.ibm.com/support/pages/node/7281717 --OR-- · Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).   For V8.5.0.0 through 8.5.5.30: · Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix that resolves DT495928 https://www.ibm.com/support/pages/node/7281717 --OR-- · Apply Fix Pack 8.5.5.31 or later (targeted availability 3Q2026). Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Upgrade IBM WebSphere Application Server Liberty to Fix Pack 26.0.0.9 or later, or apply the interim fix PH72053 for versions 17.0.0.3‑26.0.0.8, and re‑enable the sipServlet‑1.1 feature only after the fix.
  • For IBM WebSphere Application Server traditional, upgrade to Fix Pack 9.0.5.29 or later, or apply the interim fix DT495928 for versions 9.0.0.0‑9.0.5.28, and re‑enable the sipServlet‑1.1 feature only after the fix.
  • For IBM WebSphere Application Server version 8.5, upgrade to Fix Pack 8.5.5.31 or later, or apply the interim fix DT495928 for versions 8.5.0.0‑8.5.5.30.
  • If the sipServlet‑1.1 feature is not required, disable it as a temporary workaround until a patch is applied.

Generated by OpenCVE AI on August 2, 2026 at 07:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm
Ibm websphere Application Server
Ibm websphere Application Server Liberty
Vendors & Products Ibm
Ibm websphere Application Server
Ibm websphere Application Server Liberty

Wed, 29 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
Title IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Ibm Websphere Application Server Websphere Application Server Liberty
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T03:55:39.717Z

Reserved: 2026-07-02T20:25:40.691Z

Link: CVE-2026-14529

cve-icon Vulnrichment

Updated: 2026-07-29T19:13:10.365Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T19:16:44.720

Modified: 2026-08-04T14:14:17.447

Link: CVE-2026-14529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:00:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function