Executive brief
IBM WebSphere Application Server is an enterprise Java application server used by organizations to deploy and manage business-critical applications. The XD (eXtreme Scale) and Intelligent-Management features are used to optimize performance and streamline administration across application clusters. An authentication bypass vulnerability in these features allows an attacker to gain unauthorized access without valid credentials, potentially leading to unauthorized configuration changes, data exposure, or service disruption.
Technical details
The vulnerability is an authentication bypass affecting IBM WebSphere Application Server versions 9.0 and 8.5 when XD or Intelligent-Management features are enabled. The root cause lies in improper handling of HTTP permission methods and trusting HTTP method-based authorization decisions, allowing an attacker to bypass authentication checks. No prior authentication is required to exploit this vulnerability; an attacker can craft specially crafted network requests to bypass the authentication mechanism. Successful exploitation grants unauthorized access to protected administrative functions and sensitive data with high confidentiality impact. IBM recommends upgrading to patched versions 9.0.5.29 or 8.5.5.31 and later.
Affected products
- IBM WebSphere Application Server 8.5, 9.0 (prior to 8.5.5.31 and 9.0.5.29 respectively)
Timeline
- 2026-09-14: disclosed