Description
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect Leading to Phishing
Action: Patch Now
AI Analysis

Impact

IBM WebSphere Application Server prior to version 9.0.5.29 and 8.5.5.31 contains an open‑redirect flaw, classified as CWE‑601, that allows a remote attacker to craft a URL which, when visited by a user, displays a spoofed address bar while redirecting the browser to a malicious site. This can enable phishing attacks, credential theft, and may serve as a foothold for further compromise of sensitive data.

Affected Systems

Affected products are IBM WebSphere Application Server 9.0 and 8.5, including the Liberty profile. Vulnerable releases include IBM WebSphere Application Server versions from 9.0.0.0 through 9.0.5.28 and from 8.5.0.0 through 8.5.5.30.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5 and is not listed in the CISA KEV catalog. The EPSS score of 0.0022 (less than 1%) indicates a very low exploitation probability. The likely attack vector is remote, requiring only that an end‑user click a malicious link; no privileged access or technical exploitation is required beyond forging the URL. Consequently, the risk is moderate, driven mainly by user interaction and the potential to steal credentials or deliver malware via phishing.

Generated by OpenCVE AI on September 20, 2026 at 22:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply IBM WebSphere Application Server fix pack 9.0.5.29 or later to close the open‑redirect defect
  • Apply IBM WebSphere Application Server fix pack 8.5.5.31 or later to address the same flaw
  • Deploy web‑application security controls, such as a WAF, to detect and block suspicious redirect URLs, and educate users on phishing risks

Generated by OpenCVE AI on September 20, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-601
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:48.623Z

Reserved: 2026-07-10T14:15:48.930Z

Link: CVE-2026-15412

cve-icon Vulnrichment

Updated: 2026-09-15T17:27:10.643Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:38.287

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-15412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')