CVE-2026-9171: Vulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink.
IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PowerVM Novalinkto a version that resolves this vulnerability.Fixed in 2.2.1.1Patch pvm-novalink-2.2.1.1-260708 - Upgrade
Upgrade
PowerVM Novalinkto a version that resolves this vulnerability.Fixed in 2.3.3Patch pvm-novalink-2.3.3-260714
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9171?
The severity of CVE-2026-9171 is rated high, with a CVSS score of 7.5.
What type of vulnerability is CVE-2026-9171?
CVE-2026-9171 is a denial of service vulnerability affecting IBM PowerVM Novalink.
How can an attacker exploit CVE-2026-9171?
An attacker can exploit CVE-2026-9171 by sending a specially-crafted request that causes the server to consume excessive memory resources.
Which software is affected by CVE-2026-9171?
CVE-2026-9171 affects IBM PowerVM Novalink as well as IBM WebSphere Application Server and WebSphere Application Server Liberty.
What is the impact of CVE-2026-9171?
The impact of CVE-2026-9171 is that it can lead to a denial of service, making the server unavailable to legitimate users.