Executive brief
IBM WebSphere Application Server Liberty, a popular platform for building and running Java applications, is vulnerable to a security flaw when the Admin Center feature is enabled. An attacker with basic user access could force the server to make unauthorized requests to internal or external systems. This could lead to the disruption of services or the exposure of sensitive internal information that is not normally accessible from the outside network.
Technical details
A server-side request forgery (SSRF) vulnerability exists in IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.7. The flaw is specifically located within the adminCenter-1.0 feature. A remote authenticated attacker with low privileges can exploit this vulnerability to send crafted requests from the server to internal or external resources. This can result in unauthorized information disclosure or a denial of service (DoS) condition. The issue is tracked via APAR PH71841 and can be remediated by applying the provided interim fix or upgrading to Liberty Fix Pack 26.0.0.8 or later.
Affected products
- IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory