Description
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.
Published: 2026-09-14
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an attacker to bypass authentication when accessing XD or Intelligent‑Management features in IBM WebSphere Application Server. This can permit unauthorized access to management interfaces and potentially enable further exploitation of the application server. The weakness is classified as CWE‑650.

Affected Systems

IBM WebSphere Application Server 9.0 and 8.5, specifically all releases before 9.0.5.29 and 8.5.5.31. These versions provide XD or Intelligent‑Management functionality that is vulnerable until the mentioned fix packs are installed.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no current large‑scale exploitation reports. The likely attack vector is via a web request to XD or Intelligent‑Management interfaces, which can be accessed over the network. An attacker who can reach these interfaces can trick the system into accepting an unauthenticated session.

Generated by OpenCVE AI on September 15, 2026 at 07:07 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply IBM fix pack 9.0.5.29 SB0030823 or later for WebSphere Application Server 9.0, or 8.5.5.31 or later for WebSphere Application Server 8.5.
  • If the application does not require XD or Intelligent‑Management, disable those features in the server configuration to reduce the attack surface.
  • Monitor logs for unauthorized access attempts to XD or Intelligent‑Management interfaces and block any suspicious traffic.

Generated by OpenCVE AI on September 15, 2026 at 07:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-650
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T19:49:05.663Z

Reserved: 2026-07-21T02:53:33.021Z

Link: CVE-2026-16435

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:40.790

Modified: 2026-09-14T20:16:40.790

Link: CVE-2026-16435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T07:15:17Z

Weaknesses
  • CWE-650

    Trusting HTTP Permission Methods on the Server Side