8.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.
AI Analysis
Remote code execution vulnerability in IBM WebSphere Application Server via crafted HTTP request
Basic Information
ID
CVE-2026-9330
Source
ibm
Published
Jun 1, 2026 at 18:01
Affected Product
Vendor
IBM
Product
WebSphere Application Server
Version
9.0
Affected Versions
IBM WebSphere Application Server 9.0
IBM WebSphere Application Server 8.5
IBM WebSphere Application Server 8.5
CWE Classification
AI Assessment
AI Score
8.5 / 10
AI Severity
High
Vendor
IBM
Product
WebSphere Application Server
Version
8.5, 9.0