Impact
The vulnerability is a Server‑Side Request Forgery (SSRF) caused by insufficient validation of URLs in custom resources within IBM Application Gateway Operator. An attacker who can supply or modify a custom resource can lead the operator to send HTTP requests to arbitrary internal or external endpoints. The resulting ability to reach internal network services can facilitate data exfiltration, internal reconnaissance, or trigger remote code execution if the target service is vulnerable. The weakness corresponds to CWE‑918.
Affected Systems
IBM Application Gateway Operator versions 22.2 through 26.06 are affected by this SSRF flaw. Any installation of those operator releases is vulnerable until a patched version is deployed.
Risk and Exploitability
The CVSS score of 8.5 indicates a high impact and significant confidentiality, integrity, or availability risk. Because the operator runs with cluster‑level privileges, the SSRF can enable direct network access to the Kubernetes cluster or any service reachable from it. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but given the high CVSS and the nature of the flaw, the likelihood of exploitation in a targeted environment is non‑negligible.
OpenCVE Enrichment