PT-2026-71800 · Ibm · Ibm Websphere Application Server Liberty
CVE-2026-10571
·
Published
2026-08-13
·
Updated
2026-08-17
CVSS v3.1
5.7
Medium
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8
Description
An insecure deserialization issue allows a low-privileged administrative user to cause a denial of service by consuming system resources. This occurs when the
restConnector-2.0 feature is enabled. Insecure deserialization is a condition where untrusted data is used to abuse the logic of an application to execute arbitrary code or crash the system.Recommendations
As a temporary mitigation, disable the
restConnector-2.0 feature.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Websphere Application Server Liberty