PT-2026-53944 · Ibm · Ibm Websphere Application Server+1
CVE-2026-13773
·
Published
2026-06-30
·
Updated
2026-07-03
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6
Description
Approximately 50 CORBA stub classes within the
ogclient.jar file call the ORB.string to object() function using an attacker-controlled IOR string during Java deserialization. This allows an unfiltered ObjectInputStream sink in WebSphere Application Server to be used for outbound IIOP Server-Side Request Forgery (SSRF) to a host chosen by the attacker. When combined with a class-instantiation flaw in the IBM ORB getUserException function, this SSRF can be escalated to remote code execution on the calling JVM.Recommendations
Update IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6 to a patched version.
Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Websphere Application Server
Ibm Websphere Extreme Scale