Executive brief
IBM WebSphere Application Server is a Java-based application server used to host and run enterprise web applications. An authenticated administrative user with low-level privileges can modify security configuration settings, potentially exposing sensitive information or causing service disruption. This vulnerability requires administrative credentials to exploit but allows escalation of permissions beyond the user's intended role.
Technical details
The vulnerability is caused by improper privilege management (CWE-269) in IBM WebSphere Application Server versions prior to 9.0.5.29 and 8.5.5.31. An authenticated user holding a low-privilege administrative role can bypass authorization checks to modify security configuration, leading to information disclosure or denial of service. The attack vector is network-based and requires low-level administrative privileges; no additional user interaction is needed. An attacker can achieve unauthorized modification of security settings, potentially disabling security controls or accessing restricted data. Patches are available in versions 9.0.5.29 and 8.5.5.31 or later.
Affected products
- IBM WebSphere Application Server prior to 8.5.5.31 and 9.0.5.29
Timeline
- 2026-09-10: disclosed