Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via filesystem exhaustion
Action: Apply Patch
AI Analysis

Impact

IBM WebSphere Application Server versions prior to 9.0.5.29 and 8.5.5.31 can be brought down by sending a specially-crafted HTTP request to an administrative endpoint. The request forces the server to write data until the storage medium is exhausted, interrupting normal operations and denying availability to legitimate users. The root cause is a missing authorization check that allows unauthenticated or privileged requests to trigger excessive disk usage (CWE-306).

Affected Systems

The vulnerability affects IBM WebSphere Application Server, specifically all releases from V9.0.0.0 to 9.0.5.28 and from V8.5.0.0 to 8.5.5.30. IBM recommends applying Fix Pack 9.0.5.29 SB0030823 or any later pack for WebSphere 9.0, and Fix Pack 8.5.5.31 or later for WebSphere 8.5 to remediate the issue.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, with availability as the primary impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Exploitation requires network access to the administrative HTTP endpoint; the likely attack vector is a remote attacker sending the crafted request over HTTP or HTTPS. No privileged user context is explicitly required, though the administrative endpoint typically expects authentication, which may be bypassed by the flaw.

Generated by OpenCVE AI on September 10, 2026 at 23:17 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply IBM fix pack 9.0.5.29 SB0030823 or later for WebSphere 9.0, or apply fix pack 8.5.5.31 or later for WebSphere 8.5, to patch the vulnerability.
  • Restrict access to the WebSphere administrative endpoint by configuring firewalls, VPNs, or host‑based access controls so that only trusted networks or users can reach it.
  • Implement disk space monitoring and alerting to detect abnormal write activity and ensure the filesystem does not approach depletion thresholds during normal operation.

Generated by OpenCVE AI on September 10, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:-:*:*:*

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-306
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T15:41:31.825Z

Reserved: 2026-05-22T23:38:48.910Z

Link: CVE-2026-9336

cve-icon Vulnrichment

Updated: 2026-09-14T15:39:48.892Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T19:17:42.680

Modified: 2026-09-16T18:15:26.090

Link: CVE-2026-9336

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:15:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function