Executive brief
IBM WebSphere Application Server is a middleware platform that hosts enterprise Java applications. A remote attacker can inject forged entries into the server's administrative log, potentially obscuring audit trails and masking malicious activities or legitimate security events. This undermines system accountability and compliance monitoring.
Technical details
The vulnerability allows a remote attacker to inject forged log entries into IBM WebSphere Application Server's administrative log, likely due to insufficient input validation or improper sanitization of log data before writing to the audit trail. The attack vector is network-based and does not appear to require authentication or user interaction. Successful exploitation enables an attacker to manipulate audit records, potentially covering tracks of other attacks or compliance violations. Patches are available in WebSphere Application Server 9.0.5.29 and 8.5.5.31 or later.
Affected products
- IBM WebSphere Application Server 8.5 prior to 8.5.5.31, 9.0 prior to 9.0.5.29
Timeline
- 2026-09-14: disclosed