Security Advisory

CVE-2026-9006

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-22 14:46:47
Last updated 2026-06-24 03:56:08
Assigner ibm
CVSS score 7.4
State PUBLISHED

Description

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.