CVE-2026-9006: IBM WebSphere Application Server is affected by server-side request forgery
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
Other sources
IBM WebSphere Application Server is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.30 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71556
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9006?
The severity of CVE-2026-9006 is rated as critical with a score of 9.1.
How does CVE-2026-9006 affect IBM WebSphere Application Server?
CVE-2026-9006 allows an attacker to exploit server-side request forgery, potentially leading to unauthorized requests and information disclosure.
Which versions of IBM WebSphere Application Server are impacted by CVE-2026-9006?
IBM WebSphere Application Server versions 9.0 and 8.5 are affected by CVE-2026-9006.
What mitigation strategies exist for CVE-2026-9006?
To mitigate CVE-2026-9006, it is advisable to review and update the configuration of the Ajax Proxy and apply any relevant patches provided by IBM.
What is server-side request forgery (SSRF) in the context of CVE-2026-9006?
SSRF in the context of CVE-2026-9006 refers to a vulnerability that allows an attacker to send unauthorized requests from the server, potentially bypassing security controls.