CVE-2026-15887: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
Published Sep 8, 2026
·Updated
IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.
Other sources
IBM WebSphere Application Server is affected by blind server-side request forgery when processing SOAP requests.
— IBM
Affected Software
2 affected components
IBM WebSphere Application Server<=9.0
IBM WebSphere Application Server<=8.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29Patch SB0030823
Event History
Sep 8, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 14, 2026
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness