Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
Published: 2026-06-22
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in IBM WebSphere Application Server 8.5 and 9.0 resides in the Ajax Proxy component and permits a server‑side request forgery (SSRF). An attacker can cause the server to issue outbound HTTP requests to arbitrary destinations, potentially accessing internal resources or exposing sensitive data. The impact covers confidentiality and integrity because the attacker can read or modify data on internal services or abuse the server as a pivot to attack other hosts.

Affected Systems

IBM WebSphere Application Server versions 8.5.0.0 through 8.5.5.29 and 9.0.0.0 through 9.0.5.28 are affected. To mitigate the vulnerability, users should upgrade to at least fix pack 8.5.5.30 for 8.5 or fix pack 9.0.5.29 for 9.0, or apply the interim fix for APAR PH71556 that is available on IBM’s support site.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity threat. EPSS data is not available, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Based on the description, SSRF can be triggered when the Ajax Proxy is reachable and accepts requests containing attacker‑controlled URLs. An attacker who can reach the Server’s Ajax Proxy endpoint could abuse the server to launch requests to internal or external networks, potentially exposing confidential information or enabling further attacks. The CVE does not specify a public bug‑bounty or exploit example, but the flavor of SSRF vulnerabilities suggests that multiple exploitation scenarios remain possible once the attack surface is available.

Generated by OpenCVE AI on June 22, 2026 at 16:27 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH71556. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH71556 https://www.ibm.com/support/pages/node/7276400 --OR-- · Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).  For V8.5.0.0 through 8.5.5.29: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH71556 https://www.ibm.com/support/pages/node/7276400 --OR-- · Apply Fix Pack 8.5.5.30 or later (targeted availability 3Q2026).  Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Upgrade to a supported fix pack (8.5.5.30 or later for 8.5, 9.0.5.29 or later for 9.0) which includes the SSRF patch
  • If a fix pack upgrade is not immediately possible, download and apply the Interim Fix for APAR PH71556 from IBM’s support site
  • Re‑evaluate the Ajax Proxy configuration and remove or restrict it if it is not needed, reducing the attack surface for SSRF

Generated by OpenCVE AI on June 22, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 22 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
Title IBM WebSphere Application Server is affected by server-side request forgery
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-06-22T14:46:47.768Z

Reserved: 2026-05-19T13:59:27.241Z

Link: CVE-2026-9006

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-22T16:30:08Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)