CVE-2024-35154: IBM WebSphere Application Server

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.

Affected products

  • IBM WebSphere Application Server: from 8.5.0.0, up to and including 8.5.5.25; from 9.0.0.0, up to and including 9.0.5.20

Published 2024-07-09. Last modified 2026-06-17.