Blind Server-Side Request Forgery in IBM WebSphere Application Server
CVE-2026-15887

5.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 September 2026

What is CVE-2026-15887?

IBM WebSphere Application Server versions 9.0 and 8.5 are susceptible to a blind server-side request forgery (SSRF) vulnerability, which occurs when the server improperly processes SOAP requests. This flaw can lead malicious actors to access unauthorized services through targeted manipulation of the request, potentially exposing internal information and presenting further security risks.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.