Description
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
Published: 2026-08-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM WebSphere Application Server 8.5, 9.0, and Liberty Continuous delivery are affected by a flaw in the ORB component of the IBM SDK, Java Technology Edition. The vulnerability allows a malicious IIOP server to cause the target JVM to load and instantiate arbitrary Java classes. This external code loading is a CWE‑470 weakness that can give an attacker the ability to execute code within the web application server’s context, resulting in full compromise of confidentiality, integrity, and availability for the affected instance.

Affected Systems

The flaw impacts IBM WebSphere Application Server versions 8.5.0 thru 8.5.5.30, IBM WebSphere Application Server 9.0.0 and later, and IBM WebSphere Application Server Liberty Continuous delivery. Any configuration using the default IBM SDK 8 (or earlier) bundled with these server releases is susceptible until the indicated patch or Inter​​im fix is applied.

Risk and Exploitability

The CVSS score of 8.1 classifies this vulnerability as high severity. Exploitation requires the presence of a malicious remote IIOP server that can communicate with the vulnerable JVM, an attack vector that is reachable over the network. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting no large-scale public exploit is known yet; however, the high severity and the ability to execute arbitrary code warrant urgent remediation.

Generated by OpenCVE AI on August 5, 2026 at 17:38 UTC.

Remediation

Vendor Solution

For IBM WebSphere Application Server Liberty: Upgrade to IBM SDK, Java Technology Edition Version 8 SR8 FP70 refer to IBM Java SDKs for Liberty http://www-01.ibm.com/support/docview.wss For Version 9 IBM WebSphere Application Server traditional: Update to the IBM SDK, Java Technology Edition, Version 8 Service Refresh 8 FP70 using the instructions in the IBM Documentation Installing and updating IBM SDK, Java Technology Edition on distributed environments https://www.ibm.com/support/knowledgecenter/en/SSEQTP_9.0.5/com.ibm.websphere.installation.base.doc/ae/tins_installation_jdk.html then use the IBM Installation Manager to access the online product repositories https://www.ibm.com/support/knowledgecenter/SSEQTP_9.0.5/com.ibm.websphere.installation.base.doc/ae/cins_repositories.html to install the SDK or use IBM Installation Manager and access the packages from Fixcentral http://www-01.ibm.com/support/docview.wss . For Version 8.5.0.0 through 8.5.5.30 IBM WebSphere Application Server traditional:  For the IBM SDK, Java Technology Version that you use, upgrade to the minimal fix pack level of IBM WebSphere Application Server as noted in the interim fix below then apply the interim fixes: For IBM SDK Java Technology Edition Version 8 * For environments that have been upgraded to use the new default IBM SDK Version 8 bundled with IBM WebSphere Application Server Fix Pack 8.5.5.11 or later: Apply the interim fix that resolves DT496796 https://www.ibm.com/support/pages/node/7281415 : Will upgrade you to IBM SDK, Java Technology Edition, Version 8 Service Refresh 8 FP70.         OR * Apply IBM Java SDK shipped with IBM WebSphere Application Server Fix pack 31 (8.5.5.31) or later (targeted availability 3Q 2026). For Application Client for IBM WebSphere Application Server: Follow instructions above for the IBM WebSphere Application Server to download the interim fix needed for your version of the Application Client.


OpenCVE Recommended Actions

  • Upgrade to IBM SDK, Java Technology Edition Version 8 SR8 FP70 for IBM WebSphere Application Server Liberty according to IBM’s guidance.
  • For IBM WebSphere Application Server 9, update to IBM SDK, Java Technology Edition, Version 8 Service Refresh 8 FP70 using IBM Installation Manager and the online product repositories, then install the SDK as instructed by IBM.
  • For IBM WebSphere Application Server 8.5.x, apply the interim fix DT496796 that upgrades the bundled SDK to Version 8 FP70, or install Fix Pack 8.5.5.31 or later which includes the same fix.

Generated by OpenCVE AI on August 5, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 00:15:00 +0000


Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
Title Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
First Time appeared Ibm
Ibm websphere Application Server
Ibm websphere Application Server Liberty
Weaknesses CWE-470
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server_liberty:continuous:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
Ibm websphere Application Server Liberty
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Websphere Application Server Websphere Application Server Liberty
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-06T03:55:25.879Z

Reserved: 2026-05-12T13:57:37.652Z

Link: CVE-2026-8400

cve-icon Vulnrichment

Updated: 2026-08-05T17:58:31.002Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T16:17:09.657

Modified: 2026-08-10T15:57:45.763

Link: CVE-2026-8400

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-04T00:00:00Z

Links: CVE-2026-8400 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T17:45:16Z

Weaknesses
  • CWE-470

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')