Description
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
Published: 2026-07-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in IBM WebSphere Application Server 9.0, 8.5, and the Liberty profile from 17.0.0.3 through 26.0.0.7 permits an attacker to trigger a denial‑of‑service condition by sending a specially crafted HTTP request. The defect relies on improper handling of input size and falls under CWE‑400, which means the application can be overwhelmed by too large or malformed data. The result is a loss of service for legitimate users of the impacted application server.

Affected Systems

Systems running IBM WebSphere Application Server in its traditional form—versions 8.5 and 9.0—or the Liberty profile version 17.0.0.3 to 26.0.0.7 are vulnerable. These include any enterprise deployments or middleware stacks that rely on these IBM products to host web applications.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, and although the EPSS score is 0.00305—equating to a very low exploitation probability—the lack of a current KEV listing does not reduce the likelihood that the flaw will be actively exploited in the wild. Because the exploit requires only a crafted HTTP request, an attacker with network access to the target can trigger the denial of service, potentially disrupting critical services or allowing further attacks by exhausting resources. The official recommendation is to apply the latest fixes promptly to prevent exploitation.

Generated by OpenCVE AI on August 2, 2026 at 05:11 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH71585 and PH71670. For IBM WebSphere Application Server Liberty 17.0.0.3 - 26.0.0.7:· Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH71585--OR--· Apply Fix Pack 26.0.0.8 or later (targeted availability 3Q2026).For IBM WebSphere Application Server traditional:For V9.0.0.0 through 9.0.5.28:· Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH71670--OR--· Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).  For V8.5.0.0 through 8.5.5.30:· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix that resolves PH71670--OR--· Apply Fix Pack 8.5.5.31 or later (targeted availability 3Q2026).Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Apply the interim fix APAR PH71585 for Liberty or PH71670 for the traditional server, as applicable
  • Upgrade to the minimal required fix‑pack level and then install the interim fix to close the vulnerability
  • Apply the latest fix‑pack—26.0.0.8 or later for Liberty, 9.0.5.29 or later for traditional 9.0, or 8.5.5.31 or later for traditional 8.5—to fully resolve all related weaknesses

Generated by OpenCVE AI on August 2, 2026 at 05:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:-:*:*:*
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:*

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
Title IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Ibm websphere Application Server Liberty
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server___liberty:17.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server___liberty:26.0.0.7:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
Ibm websphere Application Server Liberty
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Websphere Application Server Websphere Application Server Liberty
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T18:00:19.093Z

Reserved: 2026-05-22T20:50:36.998Z

Link: CVE-2026-9322

cve-icon Vulnrichment

Updated: 2026-07-30T18:00:10.150Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T17:16:34.580

Modified: 2026-08-12T18:47:44.630

Link: CVE-2026-9322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:15:15Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption