Back Heise.De Security mechanisms in IBM WebSphere Application Server can be bypassed
Attackers can exploit several vulnerabilities in IBM WebSphere Application Server and Business Automation Workflow and, in the worst case, gain full control over systems. Security updates provide a remedy.
So far, there is no warning from the software manufacturer that attackers are already exploiting the vulnerabilities. Since both applications provide central processes and automate them in companies, administrators should install the security patches promptly.
Most software vulnerabilities affect IBM WebSphere Application Server. Three “ critical ” vulnerabilities ( CVE-2026-9311 , CVE-2026-9319 , CVE-2026-8644 ) are considered the most dangerous.
In the first case, attackers can bypass security controls and subsequently execute malicious code. The second vulnerability exclusively impacts JAX-WS endpoints with WS-Security. Due to insufficient checks, actually untrusted data is processed, allowing malicious code to enter PCs. In the third case, attackers can assume the role of another user and then do bad things. The remaining vulnerability (CVE-2026-9330 “ high ”) allows malicious code to slip through. Until the full patch is released in the third quarter, according to IBM, administrators must secure instances regarding a temporary solution in the form of an interim fix.
IBM Business Automation Workflow is vulnerable through more than ten vulnerabilities in total . Here, a vulnerability (CVE-2026-33186) in gRPC-Go is considered “critical.” This allows authentication to be bypassed. The developers assure that the security problems have been resolved in versions 24.0.0-IF009, 24.0.1-IF007, 25.0.0-IF005, and 25.0.1-IF001 .
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
