Description
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
Published: 2026-09-10
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure or denial of service via unauthorized configuration changes.
Action: Apply Patch
AI Analysis

Impact

The vulnerability permits an authenticated user with a low-privilege administrative role in IBM WebSphere Application Server to alter lead to unauthorized disclosure of information or disruption of service. The weakness is classified as CWE-269, involving improper permission assignments that enable actors to modify security settings beyond their intended authority.

Affected Systems

Affected systems are IBM WebSphere Application Server version 9.0.x before 9.0.5.29 and version 8.5.x before 8.5.5.31. Guidance states that for 9.0.0.0 through 9.0.5.28, Fix Pack 9.0.5.29 SB0030823 or later should be applied, and for 8.5.0.0 through 8.5.5.30, Fix Pack 8.5.5.31 or later should be applied.

Risk and Exploitability

The CVSS score of 6.3 indicates medium severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently widely exploited in the wild. Because the attack requires authentication, an attacker must first obtain Once authenticated, the attacker can change security settings, potentially exposing sensitive configuration data or causing denial of service. In environments where privileged accounts are compromised or misused, the risk is elevated.

Generated by OpenCVE AI on September 10, 2026 at 22:52 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply IBM Fix Pack 9.0.5.29 SB0030823 (or later) for WebSphere Application Server 9.0.x versions before 9.0.5.29.
  • Apply IBM Fix Pack 8.5.5.31 (or later) for WebSphere Application Server 8.5.x versions before 8.5.5.31.
  • After patching, verify that only authorized administrators have the necessary privileges to change security configurations and audit configuration changes to detect unauthorized modifications.

Generated by OpenCVE AI on September 10, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-269
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-11T17:44:03.635Z

Reserved: 2026-05-22T21:58:46.621Z

Link: CVE-2026-9327

cve-icon Vulnrichment

Updated: 2026-09-11T17:43:54.664Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-10T21:17:54.467

Modified: 2026-09-11T18:17:00.613

Link: CVE-2026-9327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:30:11Z

Weaknesses
  • CWE-269

    Improper Privilege Management