CVE-2026-9667: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.
Other sources
IBM WebSphere Application Server is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 9.0.5.29Patch SB0030823
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote, unauthenticated attacker could exploit it. No authentication requirement is stated in the available information.
What could exploitation allow an attacker to do?
An attacker could cause the WebSphere Application Server to send outbound requests to arbitrary endpoints, which is server-side request forgery.