Impact
This vulnerability allows a remote attacker to craft a SOAP request that causes the WebSphere Application Server to send an outgoing request to any URL specified in the request, even if the server cannot return the response to the attacker. The blind SSRF can be used to probe internal networks, access protected resources, or potentially exfiltrate data through internal channels.
Affected Systems
Versions of IBM WebSphere Application Server 9.0.x prior to fix pack 9.0.5.29 SB0030823 and 8.5.x prior to fix pack 8.5.5.31 are impacted. The affected releases are 9.0.0 through 9.0.5.28 and 8.5.0 through 8.5.5.30.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% indicates a very low exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is a crafted SOAP request sent to the application’s endpoint; successful exploitation requires network reachability to the target. Given the absence of known public exploits, the risk is considered moderate, but operators should remediate promptly to prevent potential internal reconnaissance or data access.
OpenCVE Enrichment