Impact
IBM WebSphere Application Server versions prior to 9.0.5.29 for the 9.0.x line and prior to 8.5.5.31 for the 8.5.x line contain a weakness that allows a remote attacker to bypass authentication on an admin console servlet. The vulnerability enables an attacker to gain access to administrative functions without proper credentials, as specified in the vendor’s advisory.
Affected Systems
The affected products are IBM WebSphere Application Server 8.5.x and 9.0.x. Specifically, any release before 8.5.5.31 in the 8.5.x series or before 9.0.5.29 in the 9.0.x series is vulnerable. The official fix packs are 8.5.5.31 or newer for WebSphere 8.5.x and 9.0.5.29 or newer for WebSphere 9.x.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of 0.00204, less than 1%, suggests a very low probability of exploitation. The vulnerability is described as a remote authentication bypass, implying that an attacker who can reach the admin console over the network could potentially use the flaw. The vulnerability is not listed in the CISA KEV catalog, indicating no known active, widespread exploitation.
OpenCVE Enrichment