Executive brief
IBM WebSphere Application Server is a platform used to host and run enterprise Java applications. A security flaw exists in its Session Initiation Protocol (SIP) component that could allow an unauthorized attacker to force the server to make unintended requests to internal or external systems. This could lead to the exposure of sensitive internal data, unauthorized access to internal services, or disruption of operations.
Technical details
A server-side request forgery (SSRF) vulnerability exists in IBM WebSphere Application Server (traditional and Liberty) within the SIP container component. The flaw is triggered when the 'sipServlet-1.1' feature is enabled and is associated with missing authentication for critical functions (CWE-306). A remote, unauthenticated attacker can exploit this over the network to send crafted requests, potentially gaining access to internal resources or sensitive information. IBM has released interim fixes (APAR PH72053 and DT495928) and plans to include permanent fixes in upcoming fix packs (9.0.5.29, 8.5.5.31, and 26.0.0.9).
Affected products
- IBM WebSphere Application Server 8.5, 9.0
- IBM WebSphere Application Server Liberty 17.0.0.3 - 26.0.0.8
Timeline
- 2026-07-28: advisory: Initial publication by IBM
- 2026-07-29: disclosed: NVD publication date