Executive brief
IBM WebSphere Application Server is a Java application platform used to host enterprise web applications and services. A remote attacker can exploit a vulnerability in the FileTransfer servlet to obtain sensitive information about the server's file system, potentially exposing configuration files, source code, or other confidential data.
Technical details
The vulnerability exists in the FileTransfer servlet of IBM WebSphere Application Server versions 8.5 and 9.0 prior to the patched versions (8.5.5.31 and 9.0.5.29). A remote attacker can leverage improper access controls or input validation in this servlet to read files from the server's file system. The attack requires network access to the vulnerable servlet and no authentication is specified as required.
Affected products
- IBM WebSphere Application Server 8.5 before 8.5.5.31, 9.0 before 9.0.5.29
Timeline
- 2026-09-18: disclosed