Executive brief
IBM WebSphere Application Server versions 8.5, 9.0, and Liberty are vulnerable to a flaw in the ORB (Object Request Broker) component within the bundled IBM Java SDK. A malicious IIOP server can trick the affected application into loading and instantiating arbitrary classes, potentially leading to remote code execution or data compromise. This vulnerability can be exploited over the network without user interaction or authentication.
Technical details
The vulnerability exists in the Object Request Broker (ORB) component of IBM SDK, Java Technology Edition, shipped with WebSphere Application Server. An attacker controlling a malicious IIOP (Internet Inter-ORB Protocol) server can induce loading and instantiation of arbitrary classes on the vulnerable client. The attack vector is network-based with no authentication required. Successful exploitation can result in remote code execution or unauthorized data access. Patches are available through the July 2026 CPU (Critical Patch Update) from IBM.
Affected products
- IBM WebSphere Application Server 8.5, 9.0
- IBM WebSphere Application Server Liberty Continuous delivery (various)
- IBM SDK, Java Technology Edition As shipped with WebSphere Application Server
Timeline
- 2026-08-05: disclosed
- 2026-07: patched: Patched in July 2026 IBM CPU