CVE-2017-1151: IBM WebSphere Application Server
High severity, CVSS 8.1. EPSS: 2.2% chance of exploitation in the next 30 days.
IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could allow a user to gain elevated privileges on the system. IBM Reference #: 1999293.
Affected products
- IBM WebSphere Application Server: version 8.0 only; version 8.5 only; version 8.5.5 only; version 9.0 only
Published 2017-03-20. Last modified 2026-06-17.