Executive brief
IBM WebSphere Application Server is an application server that runs business-critical enterprise applications. A remote attacker can send a specially crafted HTTP request to an administrative endpoint to cause the server to exhaust filesystem space, leading to service degradation or outage. No authentication is required to exploit this vulnerability.
Technical details
This is a denial of service vulnerability in IBM WebSphere Application Server 8.5 and 9.0 caused by improper handling of a specially crafted HTTP request sent to an administrative endpoint. The vulnerability allows a remote attacker to exhaust filesystem space on the affected server, triggering a denial of service condition. The attack requires only network access to the administrative endpoint and no authentication. Fixes are available in WebSphere Application Server 9.0.5.29 and 8.5.5.31 or later.
Affected products
- IBM WebSphere Application Server 8.5 through 8.5.5.30, 9.0 through 9.0.5.28
Timeline
- 2026-09-10: disclosed