Impact
IBM WebSphere Application Server versions prior to 9.0.5.29 and 8.5.5.31 can be brought down by sending a specially-crafted HTTP request to an administrative endpoint. The request forces the server to write data until the storage medium is exhausted, interrupting normal operations and denying availability to legitimate users. The root cause is a missing authorization check that allows unauthenticated or privileged requests to trigger excessive disk usage (CWE-306).
Affected Systems
The vulnerability affects IBM WebSphere Application Server, specifically all releases from V9.0.0.0 to 9.0.5.28 and from V8.5.0.0 to 8.5.5.30. IBM recommends applying Fix Pack 9.0.5.29 SB0030823 or any later pack for WebSphere 9.0, and Fix Pack 8.5.5.31 or later for WebSphere 8.5 to remediate the issue.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, with availability as the primary impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Exploitation requires network access to the administrative HTTP endpoint; the likely attack vector is a remote attacker sending the crafted request over HTTP or HTTPS. No privileged user context is explicitly required, though the administrative endpoint typically expects authentication, which may be bypassed by the flaw.
OpenCVE Enrichment