Impact
IBM WebSphere Application Server 8.5 and 9.0 are vulnerable to an authorization bypass, allowing an attacker to gain elevated privileges within the application. The flaw is identified as CWE-862 and can lead to unauthorized access to protected resources, potentially impacting the confidentiality and integrity of data.
Affected Systems
The vulnerability affects IBM WebSphere Application Server versions 8.5.x up to 8.5.5.30 and 9.0.x up to 9.0.5.28. The vendor recommends applying Fix Pack 8.5.5.31 for 8.5 and Fix Pack 9.0.5.29 or later for 9.0, regardless of deployment environment.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector would involve an attacker with some level of access to the application to exploit the authorization flaw. Although no remote exploitation path is explicitly described, the potential for privilege escalation remains, warranting timely patching.
OpenCVE Enrichment