Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Vulnerability is not applicable if Transport protocol is not Object Request Broker (ORB) rather IBM eXtremeIO (XIO) .Please do not use ORB as transport protocol and use XIO as transport protocol. Please follow the below document for setting XIO as transport protocol https://www.ibm.com/docs/en/SSTVLU_8.6.1/com.ibm.websphere.extremescale.doc/txsconfigxstransport.html ORB is deprecated and we have removed ORB support from 8.6.2.* version . We recommend customers to migrate to 8.6.2.*.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7278594 |
|
Tue, 30 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an attacker-chosen host; when chained with the IBM ORB's getUserException class-instantiation flaw (WAS-26), this SSRF escalates to remote code execution on the calling JVM. | |
| Title | IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used as Transport Protocol | |
| First Time appeared |
Ibm
Ibm websphere Extreme Scale |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:ibm:websphere_extreme_scale:8.6.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:websphere_extreme_scale:8.6.1.6:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm websphere Extreme Scale |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-06-30T19:37:59.403Z
Reserved: 2026-06-29T21:52:34.923Z
Link: CVE-2026-13773
Updated: 2026-06-30T19:37:50.394Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-30T20:30:04Z