CVE-2026-9006
Undergoing Analysis
Undergoing Analysis - In Progress
Server-Side Request Forgery in IBM WebSphere Application Server
Publication date: 2026-06-22
Last updated on: 2026-06-22
Assigner: IBM Corporation
Description
Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | websphere_application_server | From 9.0.5.29 (inc) |
| ibm | websphere_application_server | From 8.5.5.30 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-918 | The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. |