First published: Tue Apr 22 2025(Updated: )
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | <=9.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | <=8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-27907 is considered high due to its potential for exploiting server-side request forgery.
To fix CVE-2025-27907, apply the latest patches provided by IBM for WebSphere Application Server 8.5 and 9.0.
CVE-2025-27907 affects users of IBM WebSphere Application Server versions 8.5 and 9.0, particularly those using the Feature Pack for Web Services.
CVE-2025-27907 can facilitate unauthorized network enumeration and may lead to further attacks by allowing attackers to send requests from the vulnerable system.
Yes, CVE-2025-27907 is exploitable remotely by authenticated attackers on the affected IBM WebSphere Application Server.