9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
AI Analysis
Remote code execution vulnerability due to deserialization of untrusted data via JAX-WS endpoints with WS-Security
Basic Information
ID
CVE-2026-9319
Source
ibm
Published
Jun 1, 2026 at 17:59
Affected Product
Vendor
IBM
Product
WebSphere Application Server
Version
9.0
Affected Versions
IBM WebSphere Application Server 9.0
IBM WebSphere Application Server 8.5
IBM WebSphere Application Server 8.5
CWE Classification
AI Assessment
AI Score
9 / 10
AI Severity
Critical
Vendor
IBM
Product
WebSphere Application Server
Version
8.5, 9.0