Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.
Published: 2026-09-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Server‑Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

IBM WebSphere Application Server versions 9.0 and 8.5 are vulnerable to server‑side request forgery (SSRF). An attacker who can send a specially crafted HTTP request can cause the application server to initiate outbound network connections to arbitrary URLs without authentication. This can enable the attacker to exfiltrate sensitive data, access internal network resources, or abuse internal services. The weakness is identified as CWE‑918, indicating improper validation of user‑controlled values that influence network calls.

Affected Systems

Affected vendor and product: IBM WebSphere Application Server. Specifically, all 9.0.x releases prior to 9.0.5.29 and all 8.5.x releases prior to 8.5.5.31 are impacted. The fix packs recommended are 9.0.5.29 SB0030823 for the 9.0.x line and 8.5.5.31 for the 8.5.x line.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity impact focused on confidentiality and integrity. EPSS data is currently unavailable, so the probability of exploitation is uncertain. The vulnerability is not listed in CISA's KEV catalog, yet attackers can exploit it remotely without authentication, so organizations should prioritize patching. If patches are delayed, the risk shifts to potential internal network exposure through forged outbound requests.

Generated by OpenCVE AI on September 11, 2026 at 04:50 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Install Fix Pack 9.0.5.29 (SB0030823) or later on all IBM WebSphere Application Server 9.0.x deployments.
  • Install Fix Pack 8.5.5.31 or later on all IBM WebSphere Application Server 8.5.x deployments.
  • Apply network segmentation or firewall rules to restrict outbound connections from the WebSphere server, limiting it to only known, trusted endpoints until the patch can be applied.

Generated by OpenCVE AI on September 11, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:traditional:*:*:*

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T15:41:31.385Z

Reserved: 2026-05-26T23:59:23.213Z

Link: CVE-2026-9667

cve-icon Vulnrichment

Updated: 2026-09-14T15:39:42.793Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T21:17:54.590

Modified: 2026-09-15T17:05:49.200

Link: CVE-2026-9667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:00:10Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)