CVE-2026-9006
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD
Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
Affected (2)
Products: Ibm: Websphere Application Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.5.0.0 to 8.5.5.30 |
| Running on/with | Platform Versions |
|---|---|
Ibm Aix | All versions |
Ibm I | All versions |
Ibm Z/os | All versions |
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
References (1)
Timeline
No history available yet.