Executive brief
IBM WebSphere Application Server, a platform used to host and manage enterprise Java applications, is vulnerable to a security flaw in its Single Sign-On (SSO) component. An attacker with low-level access could send a specially crafted request to take full control of the server. This could lead to unauthorized access to sensitive business data, service disruptions, or a complete compromise of the application environment.
Technical details
IBM WebSphere Application Server versions 8.5 and 9.0 are vulnerable to an untrusted deserialization flaw (CWE-502) within the SAML Web Single Sign-On component. The vulnerability is triggered when the application improperly validates user-supplied data during the deserialization process. An attacker with low-privileged network access can exploit this by sending a crafted HTTP request. If a suitable gadget chain is present on the system classpath, the attacker can achieve remote code execution. IBM has released interim fix PH71453 to address this issue, with fix packs 9.0.5.29 and 8.5.5.30 planned for later release.
Affected products
- IBM WebSphere Application Server 9.0.0.0 through 9.0.5.28, 8.5.0.0 through 8.5.5.29
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory
- 2026-06-01: patched: Interim fix PH71453 released