medium · CVSS v3 5.3
CVE-2026-11539
IBM WebSphere Application Server 9.0 and 8.5 are vulnerable to an authentication bypass in the SOAP/JMX connector, allowing attackers to gai
Overview
IBM WebSphere Application Server 9.0 and 8.5 are vulnerable to an authentication bypass in the SOAP/JMX connector, allowing attackers to gain unauthorized access to JMX services and potentially expose sensitive configuration data. The flaw is relevant for organizations running these versions in production environments.
Description
IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.
Impact
Confidentiality: unauthorized disclosure of JMX configuration and management data. Integrity: potential unauthorized changes to application server settings. Availability: possible disruption if attacker modifies services. Impacted parties: system administrators, security teams, and any organization using the affected WebSphere versions.
Remediation
Apply IBM Fix Pack or security patch that addresses the SOAP/JMX authentication bypass. Disable or restrict the SOAP/JMX connector if not required, or block inbound traffic to the JMX port (default 8686) using firewall rules. Verify that authentication is enforced by testing JMX access with valid credentials.
Risk context
The vulnerability is rated medium (CVSS 5.3) and currently has no EPSS score, indicating moderate risk. Organizations should assess exposure promptly but the threat is not considered critical.
Affected products
- IBM WebSphere Application Server 9.0
- IBM WebSphere Application Server 8.5
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- —