Executive brief
IBM WebSphere Application Server is a widely-deployed Java application platform used to run enterprise business applications. An open redirect vulnerability allows attackers to craft deceptive URLs that redirect users to malicious websites while appearing trustworthy, enabling phishing attacks that could lead to credential theft, sensitive data disclosure, or further system compromise.
Technical details
This is a URL open redirect vulnerability (CWE-601) in IBM WebSphere Application Server 8.5, 9.0, and WebSphere Application Server - Liberty. The vulnerability allows unauthenticated, network-accessible attackers to craft specially crafted URLs that redirect users to attacker-controlled websites. No special privileges or user interaction beyond clicking a link is required. By exploiting this flaw, attackers can conduct phishing attacks, spoof trusted URLs, and deceive victims into visiting malicious sites. Patched versions are available (9.0.5.29 and 8.5.5.31 or later).
Affected products
- IBM WebSphere Application Server 8.5 prior to 8.5.5.31, 9.0 prior to 9.0.5.29
- IBM WebSphere Application Server - Liberty
Timeline
- 2026-09-14: disclosed
- 2026-09-14: advisory