CVE-2026-9322: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 17.0.0.3Patch PH71585 - Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.7Patch PH71585 - Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.8Patch PH71670 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 9.0.5.28Patch PH71670 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 9.0.5.29Patch PH71670 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.30Patch PH71670 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.31Patch PH71670
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9322?
CVE-2026-9322 has been assigned a risk score of 29, indicating a low severity level.
What vulnerability affects IBM WebSphere Application Server as noted in CVE-2026-9322?
CVE-2026-9322 indicates a denial of service vulnerability created by a crafted HTTP request.
How can I mitigate the risks associated with CVE-2026-9322?
To mitigate CVE-2026-9322, it is recommended to apply the latest security patches from IBM for WebSphere Application Server.
Are both IBM WebSphere Application Server and Liberty affected by CVE-2026-9322?
Yes, both IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by CVE-2026-9322.
When was CVE-2026-9322 published?
CVE-2026-9322 was published on July 16, 2026.