Executive brief
IBM WebSphere Application Server, a platform used for hosting enterprise Java applications, is vulnerable to a security flaw when its Ajax Proxy feature is enabled. This vulnerability allows an attacker to trick the server into making unauthorized requests to internal or external systems. Successful exploitation could lead to the exposure of sensitive internal data or allow the attacker to bypass security controls to access restricted resources.
Technical details
IBM WebSphere Application Server is vulnerable to Server-Side Request Forgery (SSRF) (CWE-918) within the Ajax Proxy component. An unauthenticated remote attacker can exploit this by sending specially crafted requests to the proxy, causing the server to initiate unauthorized outbound requests. While the attack complexity is rated as high, a successful exploit allows the attacker to bypass security protections or perform information disclosure by accessing internal services not otherwise reachable from the network. IBM has released interim fix PH71556 to address this issue, with permanent fixes planned for versions 9.0.5.29 and 8.5.5.30.
Affected products
- IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.29
Timeline
- 2026-06-16: disclosed: Initial publication of the security bulletin by IBM
- 2026-06-16: patched: Interim fix PH71556 released
- 2026-06-22: advisory: NVD publication date