Executive brief
IBM WebSphere Application Server is a middleware platform that runs enterprise Java applications for large organizations. A deserialization vulnerability in the Name Service component could allow an attacker to execute arbitrary code or cause denial of service on affected servers.
Technical details
A deserialization vulnerability exists in the Name Service component of IBM WebSphere Application Server versions 9.0 and 8.5. The vulnerability is accessible over the network without authentication, allowing unauthenticated remote attackers to trigger unsafe deserialization of untrusted data. Exploitation could lead to arbitrary code execution or information disclosure depending on gadget chains available in the runtime environment.
Affected products
- IBM WebSphere Application Server 9.0 and 8.5
Timeline
- 2026-09-18: disclosed