Executive brief
IBM i and WebSphere Application Server are affected by a security vulnerability in the Intelligent Management component of the WebServer Plug-in. An attacker who can impersonate a backend server could send malicious responses that allow them to take control of the system or cause a service outage. This could lead to unauthorized access to sensitive business data or significant operational downtime.
Technical details
The vulnerability is classified as Improper Control of Generation of Code (CWE-94) within the Intelligent Management feature of the IBM WebSphere WebServer Plug-in. It occurs when the plug-in processes responses from backend servers without sufficient validation. An attacker capable of intercepting or spoofing backend server communications (network-based attack vector) can send crafted responses to trigger remote code execution or a denial of service state. While the attack requires a high complexity (AC:H) to successfully impersonate a backend server, it requires no authentication or user interaction. IBM has released PTFs for affected IBM i versions (7.3 through 7.6) to remediate the issue.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
- IBM WebSphere Application Server 8.5, 9.0
- IBM WebSphere Application Server Liberty All versions using Intelligent Management with WebServer Plug-in
Timeline
- 2026-06-22: disclosed
- 2026-06-22: patched
- 2026-06-22: advisory