Executive brief
IBM WebSphere Application Server Liberty is a platform used to build and run Java-based applications. A security flaw allows an attacker to spoof user identities under specific conditions where applications are deployed without standard security features enabled. This could lead to unauthorized access to sensitive data or administrative functions, potentially compromising the integrity of the application and its data.
Technical details
IBM WebSphere Application Server Liberty (versions 17.0.0.3 through 26.0.0.4) is vulnerable to identity spoofing (CWE-269). The vulnerability occurs when an application is deployed without authentication and authorization configured and the 'appSecurity' feature (versions 1.0 through 5.0) is not enabled on the server. An attacker with low privileges can exploit this over the network, though the attack complexity is high due to the specific configuration requirements. Successful exploitation allows the attacker to spoof identities, potentially gaining unauthorized access to resources or performing actions as another user. IBM has released APAR PH70352 and Liberty Fix Pack 26.0.0.5 to address this issue.
Affected products
- IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.4
Timeline
- 2026-04-22: disclosed
- 2026-04-22: advisory: IBM published security bulletin 7270437
- 2026-04-22: patched: Interim fix for APAR PH70352 released; Fix Pack 26.0.0.5 scheduled for 2Q2026