Impact
IBM WebSphere Application Server versions 9.0 and 8.5 are vulnerable to server‑side request forgery (SSRF). An attacker who can send a specially crafted HTTP request can cause the application server to initiate outbound network connections to arbitrary URLs without authentication. This can enable the attacker to exfiltrate sensitive data, access internal network resources, or abuse internal services. The weakness is identified as CWE‑918, indicating improper validation of user‑controlled values that influence network calls.
Affected Systems
Affected vendor and product: IBM WebSphere Application Server. Specifically, all 9.0.x releases prior to 9.0.5.29 and all 8.5.x releases prior to 8.5.5.31 are impacted. The fix packs recommended are 9.0.5.29 SB0030823 for the 9.0.x line and 8.5.5.31 for the 8.5.x line.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity impact focused on confidentiality and integrity. EPSS data is currently unavailable, so the probability of exploitation is uncertain. The vulnerability is not listed in CISA's KEV catalog, yet attackers can exploit it remotely without authentication, so organizations should prioritize patching. If patches are delayed, the risk shifts to potential internal network exposure through forged outbound requests.
OpenCVE Enrichment