Executive brief
IBM WebSphere Application Server is a platform used to host and run enterprise Java applications. A security flaw in how the server handles JAX-WS web services could allow an unauthorized person to bypass security checks and access protected applications. This could lead to unauthorized data access or changes to business operations without a valid login.
Technical details
An authentication bypass vulnerability (CWE-287) exists in IBM WebSphere Application Server versions 8.5 and 9.0 when JAX-WS applications are deployed. The flaw allows a remote, unauthenticated attacker to bypass security constraints and gain unauthorized access to the application's web services. The vulnerability is caused by improper authentication handling within the JAX-WS component. Attackers can exploit this over the network without user interaction. IBM has released interim fix PH71648 to address this issue, with fix packs 8.5.5.30 and 9.0.5.29 planned for future release.
Affected products
- IBM WebSphere Application Server 8.5.0.0 - 8.5.5.29, 9.0.0.0 - 9.0.5.28
Timeline
- 2026-06-16: disclosed: Initial publication by IBM
- 2026-06-16: patched: Interim fix PH71648 released
- 2026-06-22: advisory: NVD published the CVE record