IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
| Vendor | Product | Versions |
|---|---|---|
| ibm | websphere application server | 9.0, 8.5 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| ibm | websphere application server liberty | cert_advisory | 90% |
| ibm | websphere application | cert_advisory | 90% |