Description
IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Blind server‑side request forgery enabling internal network exposure or data leakage
Action: Apply Fix
AI Analysis

Impact

This vulnerability allows a remote attacker to craft a SOAP request that causes the WebSphere Application Server to send an outgoing request to any URL specified in the request, even if the server cannot return the response to the attacker. The blind SSRF can be used to probe internal networks, access protected resources, or potentially exfiltrate data through internal channels.

Affected Systems

Versions of IBM WebSphere Application Server 9.0.x prior to fix pack 9.0.5.29 SB0030823 and 8.5.x prior to fix pack 8.5.5.31 are impacted. The affected releases are 9.0.0 through 9.0.5.28 and 8.5.0 through 8.5.5.30.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% indicates a very low exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is a crafted SOAP request sent to the application’s endpoint; successful exploitation requires network reachability to the target. Given the absence of known public exploits, the risk is considered moderate, but operators should remediate promptly to prevent potential internal reconnaissance or data access.

Generated by OpenCVE AI on September 20, 2026 at 22:19 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply IBM WebSphere Application Server fix pack 9.0.5.29 (SB0030823) or later for 9.0.x
  • Apply IBM WebSphere Application Server 8.5.5.31 or later for 8.5.x
  • Restrict SOAP endpoint access to trusted networks or apply IP‑based ACLs to limit incoming traffic.

Generated by OpenCVE AI on September 20, 2026 at 22:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:48.918Z

Reserved: 2026-07-15T15:23:46.560Z

Link: CVE-2026-15887

cve-icon Vulnrichment

Updated: 2026-09-15T17:27:14.847Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:38.663

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-15887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:30:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)