CVE-2026-9327: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
Other sources
IBM WebSphere Application Server could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29Patch SB0030823
Event History
Frequently Asked Questions
Does exploitation require an unauthenticated attacker?
No. Exploitation requires an authenticated user that has a low-privilege administrative role in IBM WebSphere Application Server.
What outcomes should be considered if this issue is exploited?
An attacker may be able to modify security configuration, potentially leading to information disclosure or denial of service.