Impact
The vulnerability permits an authenticated user with a low-privilege administrative role in IBM WebSphere Application Server to alter lead to unauthorized disclosure of information or disruption of service. The weakness is classified as CWE-269, involving improper permission assignments that enable actors to modify security settings beyond their intended authority.
Affected Systems
Affected systems are IBM WebSphere Application Server version 9.0.x before 9.0.5.29 and version 8.5.x before 8.5.5.31. Guidance states that for 9.0.0.0 through 9.0.5.28, Fix Pack 9.0.5.29 SB0030823 or later should be applied, and for 8.5.0.0 through 8.5.5.30, Fix Pack 8.5.5.31 or later should be applied.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently widely exploited in the wild. Because the attack requires authentication, an attacker must first obtain Once authenticated, the attacker can change security settings, potentially exposing sensitive configuration data or causing denial of service. In environments where privileged accounts are compromised or misused, the risk is elevated.
OpenCVE Enrichment