Description
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
Published: 2026-07-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Fix
AI Analysis

Impact

The vulnerability creates a denial of service condition in the HTTP channel due to unbounded allocation of resources without limits. An attacker can send crafted HTTP requests that trigger uncontrolled resource allocation, exhausting memory or networking buffers and rendering the application unavailable to legitimate users.

Affected Systems

Affected platforms include IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.7 when the servlet‑3.0 to servlet‑6.1 feature is enabled, and IBM WebSphere Application Server traditional versions 8.5.0.0 through 8.5.5.30 and 9.0.0.0 through 9.0.5.28.

Risk and Exploitability

The CVSS score of 7.5 reflects a significant impact on availability, but the EPSS score of less than 1% indicates a low probability of real‑world exploitation at the time of analysis. The vulnerability is not listed in the CISA known‑exploited catalog. Based on the description, it is inferred that the attacker would exploit the vulnerability through the HTTP channel, requiring network access and the ability to send repeated crafted requests that trigger uncontrolled allocation. While the risk of immediate exploitation is currently modest, the potential for severe service disruption warrants prompt patching.

Generated by OpenCVE AI on September 23, 2026 at 22:39 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH72191 or PH72192. To determine if a feature is enabled for WebSphere Application Server Liberty, refer to  How to determine if Liberty is using a specific feature https://www.ibm.com/support/pages/node/6553910 .   For IBM WebSphere Application Server Liberty 17.0.0.3 - 26.0.0.7 using servlet-3.0, servlet-3.1, servlet-4.0, servlet-5.0, servlet-6.0, or servlet-6.1  feature(s): · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH72191 https://www.ibm.com/support/pages/node/7277460 --OR-- · Apply Fix Pack 26.0.0.8 or later (targeted availability 3Q2026). For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH72192 https://www.ibm.com/support/pages/node/7281143 --OR-- · Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).   For V8.5.0.0 through 8.5.5.30: · Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix that resolves PH72192 https://www.ibm.com/support/pages/node/7281143 --OR-- · Apply Fix Pack 8.5.5.31 or later (targeted availability 3Q2026). Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • For Liberty installations, upgrade to the minimum required fix pack level and then apply the interim fix PH72191; alternatively, install fix pack 26.0.0.8 or later if available.
  • For traditional WebSphere Application Server, upgrade to the minimum required fix pack level and then apply the interim fix PH72192; alternatively, install fix pack 9.0.5.29 or later, or 8.5.5.31 or later.
  • Verify that the servlet features are not enabled in versions where the fix has not yet been applied and ensure the application is not exposed to untrusted networks during the patching window.

Generated by OpenCVE AI on September 23, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits. IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.

Wed, 29 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
Title IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Ibm websphere Application Server Liberty
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server___liberty:17.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server___liberty:26.0.0.7:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
Ibm websphere Application Server Liberty
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Websphere Application Server Websphere Application Server Liberty
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T20:51:29.907Z

Reserved: 2026-07-07T17:15:07.142Z

Link: CVE-2026-14981

cve-icon Vulnrichment

Updated: 2026-07-29T14:18:44.019Z

cve-icon NVD

Status : Modified

Published: 2026-07-28T21:17:27.090

Modified: 2026-09-23T21:16:57.523

Link: CVE-2026-14981

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T22:45:10Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption