Description
IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Published: 2026-07-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM WebSphere Application Server, including the Liberty profile, as well as IBM PowerVM Novalink, are vulnerable to a denial‑of‑service condition when a remote attacker sends a specially crafted request that causes the server to consume excessive memory. This uncontrolled resource consumption (CWE‑400) can exhaust available memory and render the appliance unresponsive, disrupting business operations. The vulnerability is identified with a CVSS score of 7.5, indicating a high‑severity risk.

Affected Systems

The vulnerability impacts IBM PowerVM Novalink appliances. All installations running versions earlier than pvm‑novalink‑2.2.1.1‑260708 or pvm‑novalink‑2.3.3‑260714 are affected. IBM recommends upgrading to either of those releases to remediate the issue.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, but the CVE description does not specify the attack complexity or specific vector. The EPSS score of less than 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a remote attacker would need to send a crafted request over the network to trigger memory exhaustion on the Novalink appliance.

Generated by OpenCVE AI on August 4, 2026 at 18:29 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading based on the table below. ProductVersionRemediationPowerVM Novalink 2.2.1.1 Update to pvm-novalink-2.2.1.1-260708 https://public.dhe.ibm.com/systems/virtualization/Novalink/readme/NovaLink_2.2.1.1_readme.html or Update to pvm-novalink-2.3.3-260714 https://public.dhe.ibm.com/systems/virtualization/Novalink/readme/NovaLink_2.3.3_readme.html PowerVM Novalink 2.3.3 Update to pvm-novalink-2.3.3-260714 https://public.dhe.ibm.com/systems/virtualization/Novalink/readme/NovaLink_2.3.3_readme.html


OpenCVE Recommended Actions

  • Upgrade PowerVM Novalink to pvm‑novalink‑2.2.1.1‑260708 or pvm‑novalink‑2.3.3‑260714.
  • After upgrading, restart the PowerVM Novalink service or reboot the appliance to ensure the patch is applied.
  • Configure firewall or rate‑limiting controls to restrict the volume of incoming requests to Novalink components, reducing the likelihood of repeated memory‑exhaustion attempts.

Generated by OpenCVE AI on August 4, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

Tue, 21 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Title Vulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink.
First Time appeared Ibm
Ibm powervm Novalink
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:powervm_novalink:2.2.02.2.12.2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_novalink:2.3.02.3.0.12.3.12.3.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm powervm Novalink
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Powervm Novalink
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T15:47:51.119Z

Reserved: 2026-05-21T14:37:46.761Z

Link: CVE-2026-9171

cve-icon Vulnrichment

Updated: 2026-07-21T01:51:40.366Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:30:12Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption