Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9072

Опубликовано: 22 июн. 2026
Источник: nvd
CVSS3: 8.1
CVSS3: 9.8
EPSS Низкий

Описание

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:ibm:i:*:*:*:*:*:*:*:*
Версия от 7.3 (включая) до 7.6 (включая)
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00409
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.1
github
около 1 месяца назад

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.

EPSS

Процентиль: 33%
0.00409
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-94