Impact
IBM WebSphere Application Server 9.0 and 8.5 are vulnerable to an authentication bypass that occurs when a user accesses XD or Intelligent‑Management features. The flaw allows an unauthenticated user to obtain management‑level access, which can enable further exploitation of the application server. The weakness is classified as CWE‑650, indicating a flaw in the authentication control mechanisms.
Affected Systems
IBM WebSphere Application Server 8.5 and 9.0, all releases prior to 8.5.5.31 and 9.0.5.29, respectively, are affected. These versions expose XD or Intelligent‑Management interfaces until they are patched or the features are disabled.
Risk and Exploitability
The CVSS score of 5.9 reflects a moderate impact. EPSS is reported as < 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV, suggesting no known widespread attacks. Based on the description, the likely attack vector is a network‑based web request that targets the XD or Intelligent‑Management endpoints. If an attacker can reach these interfaces, the flaw can be abused to pass authentication checks and gain control of the server management interface.
OpenCVE Enrichment