Executive brief
IBM WebSphere Application Server and IBM i systems are vulnerable to a denial of service attack. This software is used to host and manage enterprise web applications. An attacker can send specifically crafted web requests that cause the server's web plug-in to crash, potentially leading to application downtime and service interruptions for users.
Technical details
A NULL pointer dereference (CWE-476) exists in the WebSphere WebServer Plug-in component used by IBM i, WebSphere Application Server, and WebSphere Application Server Liberty. The vulnerability is triggered when the plug-in processes a specially crafted HTTP request. While the attack vector is network-based and requires no authentication, the attack complexity is rated as high. Successful exploitation allows an unauthenticated remote attacker to cause a denial of service (crash) of the web server component. IBM has released Program Temporary Fixes (PTFs) for affected IBM i versions to remediate this issue.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
- IBM WebSphere Application Server 8.5, 9.0
- IBM WebSphere Application Server Liberty All versions
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory
- 2026-06-22: patched