Executive brief
IBM WebSphere Application Server is an enterprise middleware platform that runs business-critical web applications. An authorization bypass vulnerability allows attackers to access protected resources or perform restricted operations without proper permission checks. This could lead to unauthorized data access or configuration changes affecting application security and compliance.
Technical details
The vulnerability is a missing authorization flaw (CWE-862) in IBM WebSphere Application Server versions 8.5 and 9.0. The vulnerability requires adjacent network access (not internet-reachable), has high complexity in exploitation, and does not require authentication or user interaction. A successful exploit permits limited confidentiality impact through unauthorized information disclosure. Patches are available in versions 9.0.5.29 and later, as well as 8.5.5.31 and later.
Affected products
- IBM WebSphere Application Server 8.5, 9.0 (prior to 8.5.5.31 and 9.0.5.29)
Timeline
- 2026-09-14: disclosed