Executive brief
IBM WebSphere Application Server is an enterprise Java application platform used to host and manage business-critical web applications. A vulnerability in versions 8.5 and 9.0 allows a remote attacker to inject forged entries into the server's administrative log, potentially enabling attackers to cover their tracks, create false audit trails, or mislead administrators about system activity and security events.
Technical details
This vulnerability is a log injection flaw in IBM WebSphere Application Server versions prior to 8.5.5.31 and 9.0.5.29. The exact attack vector is not fully detailed in the reference materials, but the vulnerability allows a remote attacker to inject crafted log entries into the administrative log without requiring authentication or special privileges. An attacker could exploit this to create misleading audit records, hide malicious activities, or trigger false security alerts. IBM has released patches for versions 8.5.5.31 and 9.0.5.29 and later.
Affected products
- IBM WebSphere Application Server 8.5 prior to 8.5.5.31, 9.0 prior to 9.0.5.29
Timeline
- 2026-09-14: disclosed