Impact
IBM WebSphere Application Server 8.5, 9.0, and Liberty Continuous delivery are affected by a flaw in the ORB component of the IBM SDK, Java Technology Edition. The vulnerability allows a malicious IIOP server to cause the target JVM to load and instantiate arbitrary Java classes. This external code loading is a CWE‑470 weakness that can give an attacker the ability to execute code within the web application server’s context, resulting in full compromise of confidentiality, integrity, and availability for the affected instance.
Affected Systems
The flaw impacts IBM WebSphere Application Server versions 8.5.0 thru 8.5.5.30, IBM WebSphere Application Server 9.0.0 and later, and IBM WebSphere Application Server Liberty Continuous delivery. Any configuration using the default IBM SDK 8 (or earlier) bundled with these server releases is susceptible until the indicated patch or Interim fix is applied.
Risk and Exploitability
The CVSS score of 8.1 classifies this vulnerability as high severity. Exploitation requires the presence of a malicious remote IIOP server that can communicate with the vulnerable JVM, an attack vector that is reachable over the network. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting no large-scale public exploit is known yet; however, the high severity and the ability to execute arbitrary code warrant urgent remediation.
OpenCVE Enrichment