2026-06-22 14:46CVE-2026-9006ibm
PUBLISHED5.2ApplicationCWE-918

IBM WebSphere Application Server is affected by server-side request forgery

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.

Problem type

Affected products

IBM

WebSphere Application Server

<= 7.0.2 Interim Fix 035 - AFFECTED

<= 7.0.3 Interim Fix 017 - AFFECTED

References

GitHub Security Advisories

GHSA-57wv-8v6f-4353

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF)...

https://github.com/advisories/GHSA-57wv-8v6f-4353

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-9006
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-9006",
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "dateUpdated": "2026-06-22T14:46:47.768Z",
    "dateReserved": "2026-05-19T13:59:27.241Z",
    "datePublished": "2026-06-22T14:46:47.768Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm",
        "dateUpdated": "2026-06-22T14:46:47.768Z"
      },
      "title": "IBM WebSphere Application Server is affected by server-side request forgery",
      "descriptions": [
        {
          "lang": "en",
          "value": "IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "IBM",
          "product": "WebSphere Application Server",
          "cpes": [
            "cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*"
          ],
          "versions": [
            {
              "version": "9.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.2 Interim Fix 035"
            },
            {
              "version": "8.5.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.3 Interim Fix 017"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-918 Server-Side Request Forgery (SSRF)",
              "cweId": "CWE-918",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7276600",
          "tags": [
            "vendor-advisory",
            "patch"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH"
          }
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH71556.\n\n\n\nFor IBM WebSphere Application Server traditional:\n\n\n\nFor V9.0.0.0 through 9.0.5.28:\n· Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves  PH71556 https://www.ibm.com/support/pages/node/7276400 \n--OR--\n· Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026). \n\n\n\nFor V8.5.0.0 through 8.5.5.29:\n· Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves  PH71556 https://www.ibm.com/support/pages/node/7276400 \n--OR--\n· Apply Fix Pack 8.5.5.30 or later (targeted availability 3Q2026). \n\n\n\n\n\n\n\nAdditional interim fixes may be available and linked off the interim fix download page.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH71556.</p><p><strong>For IBM WebSphere Application Server traditional:</strong></p><p><strong>For V9.0.0.0 through 9.0.5.28:</strong><br>· Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves <a href=\"https://www.ibm.com/support/pages/node/7276400\" rel=\"nofollow\">PH71556</a><br>--OR--<br>· Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).&nbsp;</p><p><strong>For V8.5.0.0 through 8.5.5.29:</strong><br>· Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves <a href=\"https://www.ibm.com/support/pages/node/7276400\" rel=\"nofollow\">PH71556</a><br>--OR--<br>· Apply Fix Pack 8.5.5.30 or later (targeted availability 3Q2026).&nbsp;</p><p></p><p>Additional interim fixes may be available and linked off the interim fix download page.</p>"
            }
          ]
        }
      ]
    }
  }
}