Executive brief
IBM WebSphere Application Server, a platform used to host and run enterprise Java applications, is vulnerable to a security flaw that could allow an attacker to take control of the server. By sending specially crafted data to the application, a remote attacker could execute unauthorized commands or code. This could lead to a complete compromise of the server, including the theft of sensitive business data or disruption of critical operations.
Technical details
A remote code execution vulnerability exists in IBM WebSphere Application Server (traditional) due to the unsafe deserialization of untrusted data (CWE-502). An attacker can exploit this by sending a specially crafted serialized object over the network. While the attack vector is network-based and requires no prior authentication, the complexity is rated as high, likely due to specific environmental requirements or the need for specific gadget chains to be present. Successful exploitation allows for arbitrary code execution in the context of the application server process. IBM has released interim fixes (APAR DT496118) and plans to include the fix in upcoming Fix Packs 8.5.5.31 and 9.0.5.29.
Affected products
- IBM WebSphere Application Server 8.5.0.0 - 8.5.5.30, 9.0.0.0 - 9.0.5.28
Timeline
- 2026-07-28: disclosed: Initial publication by IBM
- 2026-07-28: patched: Interim fixes released; Fix Packs scheduled for 3Q2026