Executive brief
IBM WebSphere Application Server is a Java-based middleware platform that runs enterprise applications. An authentication bypass vulnerability in the SOAP/JMX connector could allow an attacker to gain unauthorized administrative access to the server without valid credentials, potentially compromising the entire application environment and exposing sensitive data.
Technical details
The SOAP/JMX connector in IBM WebSphere Application Server 8.5 and 9.0 fails to properly validate authentication credentials, allowing unauthenticated remote attackers to bypass access controls via crafted SOAP requests. This enables unauthorized access to JMX management interfaces without requiring valid administrative credentials. The vulnerability is fixed in versions 8.5.5.31 and 9.0.5.29 and later.
Affected products
- IBM WebSphere Application Server 8.5 prior to 8.5.5.31, 9.0 prior to 9.0.5.29
Timeline
- 2026-09-18: disclosed