目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-15325— IBM WebSphere Application Server 输入验证错误漏洞

CVSS 8.7 · High EPSS 0.21% · P11

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 3

ベンダープロダクトVersion Rangeステータス
IBMWebSphere Application Server9.0affected
8.5affected
IBMWebSphere Application Server - Liberty17.0.0.3≤ 26.0.0.7affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-15325の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
ソース: CVE Program / CVE List V5
脆弱性説明
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
HTTP请求的解释不一致性(HTTP请求私运)
ソース: CVE Program / CVE List V5
脆弱性タイトル
IBM WebSphere Application Server 输入验证错误漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
IBM websphere application server是美国IBM公司的一个Web应用执行环境。 IBM WebSphere Application Server 9.0版本和8.5版本存在输入验证错误漏洞,该漏洞源于对TRACE请求处理不当,容易受到HTTP请求夹带攻击。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
IBMWebSphere Application Server 9.0 cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
IBMWebSphere Application Server - Liberty 17.0.0.3 ~ 26.0.0.7 cpe:2.3:a:ibm:websphere_application_server___liberty:17.0.0.3:*:*:*:*:*:*:*

II. CVE-2026-15325の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-15325のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-15325 厂商安全公告 (1)

Same Patch Batch · IBM · 2026-07-28 · 31 CVEs total

CVE-2026-144469.8 CRITICALIBM WebSphere Application Server is affected by a privilege escalation
CVE-2026-145129.8 CRITICALIBM WebSphere Application Server is affected by an unsafe deserialization and exposure of
CVE-2026-149739.3 CRITICALPath Traversal in IBM Desktop App
CVE-2026-149589.1 CRITICALOS command injection in IBM Aspera Faspex
CVE-2026-149599.1 CRITICALOS Command Injection in IBM Aspera Faspex
CVE-2026-150648.7 HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by
CVE-2026-149968.2 HIGHMultiple vulnerabilities in IBM Aspera Faspex
CVE-2026-77698.1 HIGHSQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File
CVE-2026-149748.1 HIGHIBM WebSphere Application Server is affected by cross-site scripting and deserialization v
CVE-2026-149817.5 HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by
CVE-2026-150577.5 HIGHIBM WebSphere Application Server Liberty is affected by a denial of service vulnerability
CVE-2026-152807.5 HIGHIBM WebSphere Application Server Liberty is affected by a remote code execution and path-s
CVE-2026-134637.5 HIGHDue to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability []
CVE-2026-153287.4 HIGHIBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent
CVE-2026-145287.4 HIGHIBM WebSphere Application Server is affected by an unsafe deserialization and exposure of
CVE-2026-148937.3 HIGHIBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent
CVE-2026-149767.1 HIGHIBM WebSphere Application Server Liberty is affected by a remote code execution and path-s
CVE-2026-134427.1 HIGHLangflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthe
CVE-2026-161927.1 HIGHIBM WebSphere Application Server Liberty is affected by a denial of service
CVE-2026-161847.0 HIGHIBM WebSphere Application Server is affected by an authentication bypass

Showing 20 of 31 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-15325へのコメント

まだコメントはありません


コメントを残す