CVE-2026-16187: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.
Other sources
IBM WebSphere Application Server could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 9.0.5.29Patch SB0030823
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit it by sending a crafted unauthenticated request; no prior authentication is indicated.
What could an attacker gain from successful exploitation?
Successful exploitation could bypass authentication and expose sensitive information.