Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8400

Опубликовано: 04 авг. 2026
Источник: redhat
CVSS3: 8.1

Описание

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.

A flaw was found in the ORB (Object Request Broker) component of IBM SDK, Java Technology Edition. A malicious IIOP (Internet Inter-ORB Protocol) server could exploit this vulnerability to force the loading and creation of unauthorized software components. This could lead to the execution of arbitrary code, potentially compromising the affected system.

Меры по смягчению последствий

To mitigate this issue, ensure that applications are configured to only connect to trusted IIOP servers. Restrict network access to prevent connections to untrusted or external IIOP endpoints.

Дополнительная информация

Статус:

Important
Дефект:
CWE-470
https://bugzilla.redhat.com/show_bug.cgi?id=2512497java-1.8.0-ibm: Arbitrary class loading and instantiation via malicious IIOP server

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 месяца назад

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.

CVSS3: 8.1
github
около 1 месяца назад

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.

suse-cvrf
7 дней назад

Security update for java-1_8_0-ibm

suse-cvrf
около 1 месяца назад

Security update for java-1_8_0-ibm

suse-cvrf
около 1 месяца назад

Security update for java-1_8_0-ibm

8.1 High

CVSS3