Impact
IBM WebSphere Application Server versions 8.5 and 9.0 are vulnerable to a log forgery flaw that allows a remote attacker to inject forged entries into the administrative log. This can compromise the integrity of audit trails and obscure malicious activity.
Affected Systems
The flaw affects IBM WebSphere Application Server from version 8.5.0.0 through 8.5.5.30 and from 9.0.0.0 through 9.0.5.28 across all editions. All components of the traditional and WebSphere Application Server for Java environments running those release lines are impacted.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate impact. The EPSS score of <1% indicates very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited widespread exploitation. Based on the description, it is inferred that attackers require external network access to the server’s administrative interface to craft forged log entries. While the flaw does not provide direct code execution, it can undermine security through log tampering, so timely patching is recommended.
OpenCVE Enrichment