Impact
IBM WebSphere Application Server 9.0 and 8.5 allow an attacker to inject forged entries into the administrative log, which is a CWE-117 (Log Injection) flaw that compromises log integrity and can mask malicious activity. The flaw does not grant code execution or direct system access.
Affected Systems
Vulnerable versions are IBM WebSphere Application Server 9.0.0.0 through 9.0.5.28 and 8.5.0.0 through 8.5.5.30. Applying Fix Pack 9.0.5.29 SB0030823 or later, or Fix Pack 8.5.5.31 or later, eliminates the issue.
Risk and Exploitability
The CVSS score of 4.8 and an EPSS below 1% indicate moderate severity and a low likelihood of exploitation. The vulnerability is listed as a CWE-117 (Log Injection) flaw and is not listed in CISA KEV. It is likely to be exercised remotely by sending crafted administrative requests that bypass log‑entry validation.
OpenCVE Enrichment