Impact
IBM WebSphere Application Server versions 9.0 and 8.5 contain a missing authorization flaw (CWE-862) that allows a remote attacker to send a crafted unauthenticated request and bypass authentication, thereby gaining unauthorized access to sensitive information within the application or its data stores.
Affected Systems
The affected products are IBM WebSphere Application Server 8.5 and 9.0, specifically all releases prior to 8.5.5.31 and 9.0.5.29 respectively. Users operating these versions without the corresponding fix packs are exposed to this vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high potential impact, while the EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers could exploit the flaw remotely by targeting exposed, unauthenticated endpoints and sending specially crafted requests, resulting in unauthorized data access if the vulnerability is present.
OpenCVE Enrichment