top of page
perceptive_background_267k.jpg

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side …

Published:

28 July 2026 at 22:00:00

Alert date:

29 July 2026 at 20:03:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Web Technologies

IBM WebSphere Application Server versions 9.0 and 8.5, as well as IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8, are affected by a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability is triggered when the SIP container feature (sipServlet-1.1) is enabled. SSRF vulnerabilities can allow attackers to induce the server-side application to make HTTP requests to an arbitrary domain, potentially bypassing firewalls and accessing internal services. The vulnerability has been assigned CVE-2026-14529 and is catalogued in the NVD. IBM has published a support advisory with remediation guidance. Affected organizations should review whether the sipServlet-1.1 feature is enabled and apply patches or mitigations promptly. The high criticality rating reflects the potential for significant impact in enterprise environments running WebSphere.

Technical details

Mitigation steps:

Affected products:

IBM WebSphere Application Server 9.0
IBM WebSphere Application Server 8.5
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.8

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page