Back to overview

CVE-2026-10852

MEDIUM
5.9
CVSS 3.1
Description
IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.

Metadata

CVE ID
CVE-2026-10852
State
PUBLISHED
Assigner
ibm
Reserved
2026-06-04 12:38 UTC
Published
2026-06-22 19:32 UTC
Last updated
2026-06-22 19:34 UTC
Primary CWE
CWE-476
CWE-476 NULL Pointer Dereference
Vendor / Product
IBM / i
Sources
cve.org  ·  NVD

Severity & Metrics

5.9 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products (1)
VendorProductPlatformVersions
IBM i 7.6, 7.5, 7.4, 7.3
Weakness (CWE)
CWESourceDescription
CWE-476 cna CWE-476 NULL Pointer Dereference
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.9 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Back to overview