References https://www.anquanke.com/post/id/214346 https://blog.csdn.net/weixin_29243063/article/details/157497693 https://www.cnblogs.com/supdon/p/14511452.html https://www.secrss.com/articles/24353 https://avd.aliyun.com/detail?id=AVD-2015-7450 https://www.tenablecloud.cn/plugins/nessus/87171 https://hu3sky.github.io/2020/10/19/CVE-2020-4643%EF%BC%9AWebSphere%20XXE%20%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90%E4%BB%A5%E5%8F%8A%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E5%85%A5%E5%8F%A3%E6%8C%96%E6%8E%98/ https://nosec.org/m/share/4541.html https://stack.chaitin.com/vuldb/detail/de80aada-9eaf-4929-8d1e-3dd46773e9a9 https://comate.baidu.com/zh/page/exxw154s6yz https://qkl.seebug.org/vuldb/ssvid-89727 https://zhuanlan.zhihu.com/p/719072722 https://cert.360.cn/report/detail?id=3d016bdef66b8e29936f8cb364f265c8 https://juejin.cn/post/7173287202015674405 https://cloud.tencent.com/developer/article/1708174 https://www.gxust.edu.cn/gxkjdxhywzywz/info/1214/3413.htm https://blog.nsfocus.net/websphere-cve-2020-4450-0605/ https://www.sohu.com/a/909738096_121124359 https://www.secpulse.com/archives/138165.html https://zhzhdoai.github.io/2020/08/15/WebSphere-IIOP%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96-CVE-2020-4450/ https://www.acunetix.com/vulnerabilities/web/ibm-websphere-rce-java-deserialization-vulnerability/ https://www.tenable.com/plugins/nessus/87171 https://www.sentinelone.com/vulnerability-database/cve-2025-36038/ https://www.rapid7.com/db/modules/exploit/windows/misc/ibm_websphere_java_deserialize/ https://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/ https://www.thezdi.com/blog/2020/9/29/exploiting-other-remote-protocols-in-ibm-websphere https://github.com/Coalfire-Research/java-deserialization-exploits/blob/main/WebSphere/websphere_rce.py https://www.exploit-db.com/exploits/41613 https://www.thezdi.com/blog/2020/7/20/abusing-java-remote-protocols-in-ibm-websphere
Related VulnerabilitiesPoCibm-websphere-ssrf: IBM WebSphere HCL Digital Experience - Server-Side Request ForgeryPoCCVE-2015-7450: IBM WebSphere Java Object Deserialization - Remote Code ExecutionPoCCVE-2021-27748: IBM WebSphere HCL Digital Experience - Server-Side Request ForgeryPoCibm-friendly-path-exposure: IBM Websphere Friendly Path ExposurePoCibm-websphere-xml: IBM WebSphere Application - Source File ExposureIBM WebSphere Application Server 存在远程代码执行漏洞IBM WebSphere服务端ssrf(CVE-2021-27748)IBM WebSphere Application Server Portal 存在 SSRF 漏洞WebSphere敏感文件读取漏洞(CVE-2019-4505)IBM WebSphere Application Server IIOP 协议存在远程代码执行漏洞