ZeroHour

CVE-2025-27907

CVSS 3.1
2.7 low
EPSS
<1%p26
Published
()
Modified
Description

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

Vendors
ibm
Products
websphere application server
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.