Description
IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.
Published: 2026-06-22
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WebSphere Web Server Plug‑in component is vulnerable to remote code execution and denial of service when an attacker impersonates the application server and sends crafted responses to the plug‑in. This flaw enables an attacker to run arbitrary code on the IBM i system and disrupt the availability of the affected services. The vulnerability is driven by improper validation of responses from the application server, effectively allowing a malicious actor to control the plug‑in’s execution path.

Affected Systems

IBM i releases 7.3, 7.4, 7.5 and 7.6, together with IBM WebSphere Application Server and IBM WebSphere Application Server Liberty, are affected. The official fix is distributed as PTF 7.6SJ10122 for release 7.6, PTF 7.5SJ10121 for release 7.5, PTF 7.4SJ10120 for release 7.4 and PTF 7.3SJ10119 for release 7.3. Users of unsupported or older versions are strongly advised to upgrade to a supported, patched version of the product.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog, implying no documented exploits to date. However, the attack is believed to be remotely attainable through network access to the WebSphere Web Server Plug‑in, which can be exploited by an attacker who can impersonate the application server. Because the flaw permits arbitrary code execution, the risk to confidentiality, integrity and availability is considerable if exploited.

Generated by OpenCVE AI on June 22, 2026 at 16:29 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ10122 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10122 7.5SJ10121 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10121 7.4SJ10120 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10120 7.3SJ10119 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10119 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTF patches 7.6SJ10122, 7.5SJ10121, 7.4SJ10120 or 7.3SJ10119, whichever corresponds to the installed release.
  • Restrict inbound network access to the WebSphere Web Server Plug‑in component using firewalls or network segmentation so that only trusted hosts can communicate with it.
  • Monitor for anomalous network traffic and system behavior that might indicate exploitation attempts, and review system logs regularly for signs of sabotage or unauthorized activity.

Generated by OpenCVE AI on June 22, 2026 at 16:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 22 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.
Title IBM i is Affected By Denial of Service, HTTP Request Smuggling, and Remote Code Execution Vulnerabilities in IBM WebSphere Application Server Liberty [, , , , ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-06-22T14:19:43.229Z

Reserved: 2026-05-18T18:06:05.131Z

Link: CVE-2026-8858

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-22T19:30:06Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')