TROYANOSYVIRUS
Volver a CVEs

CVE-2025-27907

MEDIUM
4.1

Descripcion

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

Detalles CVE

Puntuacion CVSS v3.14.1
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosHIGH
Interaccion usuarioNONE
Publicado4/22/2025
Ultima modificacion7/18/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

hp:hp-uxibm:aixibm:iibm:websphere_application_serveribm:z\/oslinux:linux_kernelmicrosoft:windowsoracle:solaris

Debilidades (CWE)

CWE-918

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.