CVE-2026-8633 Details
Description
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.
A remote code execution vulnerability has been identified in the IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty, specifically in versions 8.5 and 9.0. This vulnerability allows for code execution through the Web Server Plug-ins by sending a specially crafted request.
Users are advised to apply the currently available Web Server Plug-ins interim fix or fix pack that contains the fix for APAR PH71342. For Web Server Plug-ins for IBM WebSphere Application Server V9.0.0.0 through 9.0.5.27, upgrade to the required minimal fix pack level and then apply the Web Server Plug-ins Interim Fix for PH71342. Alternatively, Web Server Plug-ins Fix Pack 9.0.5.28 or later can be applied. For V8.5.0.0 through 8.5.5.29, the same interim fix process applies, or Web Server Plug-ins Fix Pack 8.5.5.30 or later can be applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7274072 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm websphere application server | >= 8.5.0.0, <= 8.5.5.29 >= 9.0.0.0, <= 9.0.5.27 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | Reanalysis | [email protected] |
| May 27, 2026 | Initial Analysis | [email protected] |
| May 26, 2026 | New CVE Received | [email protected] |