CVE-2026-9338: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to reduced availability of the affected service.
Other sources
IBM WebSphere Application Server is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to reduced availability of the affected service.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5.xto a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0.xto a version that resolves this vulnerability.Fixed in 9.0.5.29Patch SB0030823
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit it by sending a specially crafted request. No privileges or user interaction are required.
What is the expected impact on an affected server?
Successful exploitation can cause excessive resource consumption and reduce availability of the affected WebSphere Application Server service. The provided information describes a denial-of-service impact and does not indicate confidentiality or integrity impact.
Which versions are identified as affected?
The affected version ranges stated are WebSphere Application Server 9.0 prior to 9.0.5.29 and 8.5 prior to 8.5.5.31.