Executive brief
IBM WebSphere Application Server, a platform used to host and manage enterprise Java applications, is affected by a security flaw that could expose sensitive information. An attacker could potentially access confidential data that has been improperly recorded in system log files. This exposure could lead to the compromise of credentials or other private operational details, though the attack requires specific conditions to be met.
Technical details
IBM WebSphere Application Server traditional is vulnerable to CWE-532 (Insertion of Sensitive Information into Log File). The vulnerability allows a remote attacker to obtain sensitive information by accessing log files where the application has inadvertently recorded confidential data. The attack vector is network-based with high complexity (AC:H), meaning specific environmental conditions or configurations must be met for successful exploitation. IBM has released interim fix PH72166 to address this issue, with permanent fixes planned for versions 9.0.5.29 and 8.5.5.31.
Affected products
- IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.30
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
- 2026-07-28: patched: Interim fix PH72166 released