CVE-2026-14512

IBM · WebSphere Application Server

IBM WebSphere Application Server versions 9.0 and 8.5 are susceptible to pre-authentication unsafe deserialization, enabling remote attackers to bypass authentication or execute arbitrary code.

Executive summary

A critical deserialization flaw in IBM WebSphere Application Server allows unauthenticated remote attackers to execute arbitrary code or bypass security controls.

Vulnerability

The application is vulnerable to unsafe deserialization of untrusted data, which can be triggered by a remote, unauthenticated attacker. This flaw allows for the execution of arbitrary code or unauthorized access to administrative functions by manipulating serialized objects.

Business impact

With a CVSS score of 9.8, this vulnerability poses a severe risk to organizational infrastructure. Successful exploitation results in total system compromise, potentially exposing sensitive data, enabling the installation of persistent backdoors, and facilitating further attacks against the internal network.

Remediation

Immediate Action: Apply the relevant interim fix for APAR PH72166 or upgrade to Fix Pack 9.0.5.29 or later as specified in the IBM security advisory.

Proactive Monitoring: Monitor application server logs for unexpected deserialization errors and anomalous inbound traffic patterns targeting administrative ports or services.

Compensating Controls: Deploy a WAF with rules configured to detect and block serialized Java objects in HTTP requests that do not originate from trusted sources.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability and its potential for unauthenticated remote exploitation, immediate patching is required. Administrators must follow the specific instructions provided in the IBM support portal to ensure the relevant APAR fixes are correctly applied to their environments.