Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-8858

Опубликовано: 22 июн. 2026
Источник: nvd
CVSS3: 7.5
CVSS3: 8.8
EPSS Низкий

Описание

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:ibm:i:*:*:*:*:*:*:*:*
Версия от 7.3 (включая) до 7.6 (включая)
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.0026
Низкий

7.5 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.5
github
около 1 месяца назад

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.

EPSS

Процентиль: 18%
0.0026
Низкий

7.5 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-94