Impact
The vulnerability allows an attacker to bypass authentication when accessing XD or Intelligent‑Management features in IBM WebSphere Application Server. This can permit unauthorized access to management interfaces and potentially enable further exploitation of the application server. The weakness is classified as CWE‑650.
Affected Systems
IBM WebSphere Application Server 9.0 and 8.5, specifically all releases before 9.0.5.29 and 8.5.5.31. These versions provide XD or Intelligent‑Management functionality that is vulnerable until the mentioned fix packs are installed.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no current large‑scale exploitation reports. The likely attack vector is via a web request to XD or Intelligent‑Management interfaces, which can be accessed over the network. An attacker who can reach these interfaces can trick the system into accepting an unauthenticated session.
OpenCVE Enrichment