{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "notes": [
            {
                "category": "summary",
                "text": "IBM WebSphere Application Server could provide weaker than expected security."
            }
        ],
        "publisher": {
            "category": "vendor",
            "contact_details": "$PLACEHOLDER",
            "name": "IBM",
            "namespace": "https://www.ibm.com"
        },
        "references": [
            {
                "category": "external",
                "summary": "Security Bulletin web URL",
                "url": "https://www.ibm.com/support/pages/node/7260217"
            },
            {
                "category": "self",
                "summary": "Canonical link to Security Bulletin CSAF",
                "url": "https://public.dhe.ibm.com/ibmdl/export/pub/software/websphere/automation/bulletins/7260217.json"
            }
        ],
        "title": "IBM WebSphere Application Server could provide weaker than expected security (CVE-2025-13333)",
        "tracking": {
            "current_release_date": "2026-03-09T12:00:00.000Z",
            "generator": {
                "date": "2026-03-09T12:00:00.000Z",
                "engine": {
                    "name": "IBM WSA CSAF Script Suite (Internal Use Only)",
                    "version": "1.0.0"
                }
            },
            "id": "7260217",
            "initial_release_date": "2026-03-09T12:00:00.000Z",
            "revision_history": [
                {
                    "date": "2026-03-09T12:00:00.000Z",
                    "number": "1",
                    "summary": "Initial Publication"
                }
            ],
            "status": "final",
            "version": "1"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=9.0.5.24|<=9.0.5.26",
                                        "product": {
                                            "name": "IBM WebSphere Application Server 9.0 vers:vrmf/>=9.0.5.24|<=9.0.5.26",
                                            "product_id": "CSAFPID-0001"
                                        }
                                    },
                                    {
                                        "category": "patch_level",
                                        "name": "9.0.5.27",
                                        "product": {
                                            "name": "IBM WebSphere Application Server 9.0.5.27",
                                            "product_id": "CSAFPID-0003"
                                        }
                                    }
                                ],
                                "name": "9.0",
                                "category": "product_version"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=8.5.5.28|<=8.5.5.29",
                                        "product": {
                                            "name": "IBM WebSphere Application Server 8.5 vers:vrmf/>=8.5.5.28|<=8.5.5.29",
                                            "product_id": "CSAFPID-0004"
                                        }
                                    },
                                    {
                                        "category": "patch_level",
                                        "name": "8.5.5.30",
                                        "product": {
                                            "name": "IBM WebSphere Application Server 8.5.5.30",
                                            "product_id": "CSAFPID-0005"
                                        }
                                    }
                                ],
                                "name": "8.5",
                                "category": "product_version"
                            }
                        ],
                        "category": "product_name",
                        "name": "WebSphere Application Server"
                    }
                ],
                "category": "vendor",
                "name": "IBM"
            }
        ],
        "full_product_names": [
            {
                "name": "z/OS",
                "product_id": "CSAFPID-0006"
            },
            {
                "name": "IBM i",
                "product_id": "CSAFPID-0007"
            },
            {
                "name": "Windows",
                "product_id": "CSAFPID-0008"
            },
            {
                "name": "Mac OS",
                "product_id": "CSAFPID-0009"
            },
            {
                "name": "AIX",
                "product_id": "CSAFPID-0010"
            },
            {
                "name": "Linux",
                "product_id": "CSAFPID-0011"
            },
            {
                "name": "PH68976",
                "product_id": "CSAFPID-0002"
            }
        ],
        "product_groups": [
            {
                "group_id": "CSAFGID-0001",
                "product_ids": [
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011"
                ],
                "summary": "Operating Systems"
            }
        ],
        "relationships": [
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server 9.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0012"
                },
                "product_reference": "CSAFPID-0002",
                "relates_to_product_reference": "CSAFPID-0001"
            },
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server 8.5 APAR Remediation Action",
                    "product_id": "CSAFPID-0013"
                },
                "product_reference": "CSAFPID-0002",
                "relates_to_product_reference": "CSAFPID-0004"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2025-13333",
            "notes": [
                {
                    "category": "description",
                    "text": "IBM WebSphere Application Server could provide weaker than expected security during system administration of security settings."
                },
                {
                    "category": "details",
                    "title": "Required next steps",
                    "text": true
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-0003",
                    "CSAFPID-0005"
                ],
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0004"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Complete CVSS v3 Guide",
                    "url": "https://www.first.org/cvss/user-guide"
                },
                {
                    "category": "external",
                    "summary": "On-line Calculator v3",
                    "url": "https://www.first.org/cvss/calculator/3.0"
                },
                {
                    "category": "external",
                    "summary": "Complete CVSS v4 Guide",
                    "url": "https://www.first.org/cvss/user-guide"
                },
                {
                    "category": "external",
                    "summary": "On-line Calculator v4",
                    "url": "https://www.first.org/cvss/calculator/4.0"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH68976 and carefully follow the instructions for steps required after fix installation.",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Apply Fix Pack 9.0.5.27 or later (targeted availability 1Q2026) and carefully follow the instructions in PH68976 for steps required after fixpack installation.",
                    "product_ids": [
                        "CSAFPID-0001"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Apply Fix Pack 8.5.5.30 or later (targeted availability 3Q2026) and carefully follow the instructions in PH68976 for steps required after fixpack installation.",
                    "product_ids": [
                        "CSAFPID-0004"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "attackComplexity": "HIGH",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "NONE",
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "NONE",
                        "privilegesRequired": "HIGH",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0004"
                    ]
                }
            ]
        }
    ]
}