Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
Published: 2026-06-01
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM WebSphere Application Server versions 8.5 and 9.0 are vulnerable to remote code execution caused by a bypass of security controls. The vulnerability is classified as CWE‑94, an input injection weakness, and can lead to complete loss of confidentiality, integrity, and availability. The description indicates that remote code execution is possible, but it does not specify the privilege level at which the code would run – that is an inferred potential.

Affected Systems

The affected platforms are IBM WebSphere Application Server 9.0 and 8.5. For 9.0, the problem exists in versions from 9.0.0.0 through 9.0.5.28; for 8.5 it exists from 8.5.0.0 through 8.5.5.29. IBM recommends applying the interim fix PH71453 or upgrading to fix packs 9.0.5.29 or later for 9.0, and 8.5.5.30 or later for 8.5.

Risk and Exploitability

The CVSS score is 9, indicating a high severity level. EPSS data is not available, so the exact likelihood of exploitation is unknown but the risk is considered significant due to the remote code execution capability. The vulnerability is not listed in the CISA KEV catalog, but the lack of a KEV listing does not diminish the threat. Based on the description, it is inferred that the attack vector may involve network‑exposed WebSphere interfaces, where an attacker could send specially crafted requests to trigger code execution. The impact is immediate and severe, so any exposed instance should be patched without delay.

Generated by OpenCVE AI on June 1, 2026 at 21:39 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH71453. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH71453 https://www.ibm.com/support/pages/node/7274233 --OR-- · Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).  For V8.5.0.0 through 8.5.5.29: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH71453 https://www.ibm.com/support/pages/node/7274233 --OR-- · Apply Fix Pack 8.5.5.30 or later (targeted availability 3Q2026).  Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Install the interim fix PH71453 from the IBM support site
  • Upgrade the server to the minimal required fix pack level, then apply the interim fix
  • Apply Fix Pack 9.0.5.29 or later for WebSphere 9.0, or Fix Pack 8.5.5.30 or later for WebSphere 8.5

Generated by OpenCVE AI on June 1, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 04 Jun 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:traditional:*:*:*

Mon, 01 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
Title IBM WebSphere Application Server is affected by remote code execution
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-06-02T03:56:05.941Z

Reserved: 2026-05-22T18:36:49.976Z

Link: CVE-2026-9311

cve-icon Vulnrichment

Updated: 2026-06-01T21:20:02.515Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-01T19:16:55.537

Modified: 2026-06-04T16:53:09.640

Link: CVE-2026-9311

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-01T22:00:12Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')