Executive brief
IBM WebSphere Application Server, a widely used platform for hosting enterprise Java applications, is affected by a security flaw in its SOAP/JMX management connector. An attacker with low-level access could exploit this to execute unauthorized code on the server. This could lead to a complete takeover of the application server, resulting in the theft of sensitive data, service disruption, or further attacks on the internal corporate network.
Technical details
A remote code execution vulnerability exists in IBM WebSphere Application Server versions 8.5 and 9.0 within the SOAP/JMX connector. The flaw is rooted in the deserialization of untrusted data (CWE-502), allowing an attacker to execute arbitrary commands. While the attack vector is network-based, exploitation requires low-level privileges (PR:L) and involves high complexity (AC:H). Successful exploitation results in a scope change (S:C), granting the attacker significant control over the host system. IBM has released interim fix PH71714 and plans to include the fix in upcoming Fix Packs 9.0.5.29 and 8.5.5.30.
Affected products
- IBM WebSphere Application Server 9.0.0.0 through 9.0.5.28, 8.5.0.0 through 8.5.5.29
Timeline
- 2026-06-23: disclosed: Initial publication by IBM
- 2026-06-23: patched: Interim fix PH71714 released
- 2026-07-30: advisory: NVD publication date