Impact
IBM WebSphere Application Server versions 9.0 and 8.5 prior to fix packs 9.0.5.29 and 8.5.5.31 contain a security bypass caused by improper authentication controls. The flaw allows a local attacker to elevate privileges and gain unauthorized access to protected resources. The issue is identified as CWE‑94.
Affected Systems
Affected products include IBM WebSphere Application Server 9.0 and 8.5 across all sub‑versions that have not received the listed fix packs. The specific vulnerable versions are 9.0.x up to 9.0.5.28 and 8.5.x up to 8.5.5.30. Security patches are provided in Fix Pack 9.0.5.29 (SB0030823) and Fix Pack 8.5.5.31, respectively; any later fix pack also contains the remediation.
Risk and Exploitability
The CVSS score of 6.7 indicates that the vulnerability is of moderate severity. Existing exploitation data for this flaw is not available, and it is not currently listed in the CISA KEV catalog. Because the attack requires local access and the attacker must have some presence on the system, the likelihood of exploitation is considered moderate. The flaw’s exploitation path involves an authenticated session escalation, so protection measures such as proper authentication handling and least‑privilege enforcement are essential.
OpenCVE Enrichment