CVE-2026-9319: IBM WebSphere Application Server is affected by a remote code execution vulnerability
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
Other sources
IBM WebSphere Application Server is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional (8.5)to a version that resolves this vulnerability.Fixed in 8.5.5.30Patch PH71454 - Upgrade
Upgrade
IBM WebSphere Application Server traditional (9.0)to a version that resolves this vulnerability.Fixed in 9.0.5.29Patch PH71454
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9319?
CVE-2026-9319 has a critical severity rating of 9.
What software is affected by CVE-2026-9319?
CVE-2026-9319 affects IBM WebSphere Application Server versions 9.0 and 8.5.
How do I fix CVE-2026-9319?
To fix CVE-2026-9319, apply the currently available interim fix or fix pack that contains the fix for APAR PH71454.
What type of vulnerability is CVE-2026-9319?
CVE-2026-9319 is classified as a remote code execution vulnerability due to deserialization of untrusted data.
Is CVE-2026-9319 exploitable remotely?
Yes, CVE-2026-9319 can be exploited remotely, making it a significant security risk.