CVE-2026-9320: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Other sources
IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.7 - Upgrade
Upgrade
IBM WebSphere Application Serverto a version that resolves this vulnerability.Fixed in 8.5.5.30 - Upgrade
Upgrade
IBM WebSphere Application Serverto a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71370 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71631
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9320?
The severity of CVE-2026-9320 is high with a score of 7.5.
What products are affected by CVE-2026-9320?
CVE-2026-9320 affects IBM WebSphere Application Server 9.0, 8.5, and IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.6.
How do I fix CVE-2026-9320?
To mitigate CVE-2026-9320, it is recommended to update to the latest version of IBM WebSphere Application Server or apply the relevant security patches.
What type of attack does CVE-2026-9320 enable?
CVE-2026-9320 enables a denial of service attack, which can cause the server to consume excessive memory resources.
What is the exploitability of CVE-2026-9320?
CVE-2026-9320 has an exploitability score of 0.00323, indicating a low likelihood of exploitation.