Executive brief
IBM WebSphere Application Server and WebSphere Liberty are affected by a critical vulnerability in their web server plug-in component, which is used to connect web servers to the application server. An attacker can exploit this flaw to remotely execute arbitrary code on the server by sending a specially crafted network request. This could lead to a complete takeover of the affected system, unauthorized access to sensitive data, and disruption of business operations.
Technical details
A remote code execution vulnerability exists in the IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty (versions 8.5 and 9.0). The flaw is categorized as code injection (CWE-94) and resides within the plug-in component that handles requests between the web server and the application server. An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP request to the web server. Successful exploitation allows for arbitrary code execution with the privileges of the web server process. IBM has released interim fixes under APAR PH71342 and recommends upgrading to fix packs 9.0.5.28 or 8.5.5.30.
Affected products
- IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5.0.0 through 8.5.5.29, 9.0.0.0 through 9.0.5.27
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory: IBM Security Bulletin published