CVE-2026-9336: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.
Other sources
IBM WebSphere Application Server is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 9.0.5.29Patch SB0030823
Event History
Frequently Asked Questions
Which deployments are exposed to remote exploitation?
Deployments with an administrative endpoint that a remote attacker can send HTTP requests to are exposed. The available information does not state whether authentication or any particular configuration is required.
What does an attacker need to do to trigger the issue?
An attacker needs to send a specially crafted HTTP request to an administrative endpoint. Successful exploitation can cause filesystem space exhaustion and result in denial of service.