Executive brief
IBM WebSphere Application Server Liberty, a popular platform for building and running Java applications, is affected by a security flaw when the API discovery feature is enabled. An attacker with basic user access can trick the server into making unauthorized requests to internal systems or external websites. This could lead to the exposure of sensitive internal data or allow the attacker to bypass security controls to reach restricted parts of the corporate network.
Technical details
A server-side request forgery (SSRF) vulnerability exists in IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.7. The flaw is located within the apiDiscovery-1.0 feature, which is used to discover and document REST APIs. A remote authenticated attacker with low privileges can exploit this vulnerability by sending a specially crafted request, causing the server to perform unauthorized network requests. This can be used to scan internal networks, access metadata services, or pivot to other internal systems that are not directly accessible from the internet. IBM has released interim fix PH71873 and recommends upgrading to Liberty Fix Pack 26.0.0.8 or later.
Affected products
- IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.7
Timeline
- 2026-06-30: disclosed: Initial advisory publication by IBM
- 2026-06-30: advisory: NVD record published