← Back to CVE List
CVE-2026-16187NVD
Vulnerability Summary
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.
CVSS v3.1 Base Metrics — Score 6.5 (MEDIUM)
Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- IBM WebSphere Application Server >= 9.0
- IBM WebSphere Application Server >= 8.5
Not provided by cveorg for this CVE.