CVE-2026-14529

IBM · WebSphere Application Server

IBM WebSphere Application Server is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled, potentially allowing unauthorized network requests.

Executive summary

A critical server-side request forgery vulnerability in IBM WebSphere Application Server permits unauthenticated attackers to perform unauthorized requests, necessitating immediate patching.

Vulnerability

The application fails to properly validate requests within the SIP container feature (sipServlet-1.1), leading to SSRF. This vulnerability is exploitable by unauthenticated remote attackers.

Business impact

The CVSS score of 9.4 indicates a critical severity level, reflecting the potential for total system impact. An attacker could leverage this SSRF flaw to interact with internal services that are not exposed to the public internet, potentially leading to unauthorized data access, internal service disruption, or further exploitation of backend infrastructure.

Remediation

Immediate Action: Apply the vendor-provided interim fix or fix pack that resolves APAR PH72053 or DT495928 as detailed in the IBM security advisory.

Proactive Monitoring: Review application logs for unusual outbound network traffic or unexpected internal API calls originating from the WebSphere server.

Compensating Controls: If patching is delayed, disable the sipServlet-1.1 feature in the Liberty configuration if it is not required for your business operations.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for unauthenticated exploitation, this vulnerability poses a significant risk to internal network segments. Organizations should prioritize the application of the specified IBM patches or disable the vulnerable feature immediately to prevent unauthorized access.