{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "notes": [
            {
                "category": "summary",
                "text": "There are mulitple vulnerabilities in the Apache CXF library that affect IBM WebSphere Application Server and affect WebSphere Application Server Liberty when the jaxrs-2.0, jaxrs-2.1, jaxws-2.2, xmlWS-3.0, or xmlWS-4.0 features are enabled."
            }
        ],
        "publisher": {
            "category": "vendor",
            "contact_details": "$PLACEHOLDER",
            "name": "IBM",
            "namespace": "https://www.ibm.com"
        },
        "references": [
            {
                "category": "external",
                "summary": "Security Bulletin web URL",
                "url": "https://www.ibm.com/support/pages/node/7283567"
            },
            {
                "category": "self",
                "summary": "Canonical link to Security Bulletin CSAF",
                "url": "https://public.dhe.ibm.com/ibmdl/export/pub/software/websphere/automation/bulletins/7283567.json"
            }
        ],
        "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities due to Apache CXF (CVE-2026-57819, CVE-2026-54225, CVE-2026-64958)",
        "tracking": {
            "current_release_date": "2026-08-12T12:00:00.000Z",
            "generator": {
                "date": "2026-08-12T12:00:00.000Z",
                "engine": {
                    "name": "IBM WSA CSAF Script Suite (Internal Use Only)",
                    "version": "1.0.0"
                }
            },
            "id": "7283567",
            "initial_release_date": "2026-08-12T12:00:00.000Z",
            "revision_history": [
                {
                    "date": "2026-08-12T12:00:00.000Z",
                    "number": "1",
                    "summary": "Initial Publication"
                }
            ],
            "status": "final",
            "version": "1"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=26.0.0.1|<=26.0.0.8",
                                        "product": {
                                            "name": "IBM WebSphere Application Server Liberty 26.0 vers:vrmf/>=26.0.0.1|<=26.0.0.8",
                                            "product_id": "CSAFPID-0001"
                                        }
                                    }
                                ],
                                "name": "26.0",
                                "category": "product_version"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=17.0.0.3|<=17.0.0.4",
                                        "product": {
                                            "name": "IBM WebSphere Application Server Liberty 17.0 vers:vrmf/>=17.0.0.3|<=17.0.0.4",
                                            "product_id": "CSAFPID-0002"
                                        }
                                    }
                                ],
                                "name": "17.0",
                                "category": "product_version"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=18.0.0.1|<=18.0.0.4",
                                        "product": {
                                            "name": "IBM WebSphere Application Server Liberty 18.0 vers:vrmf/>=18.0.0.1|<=18.0.0.4",
                                            "product_id": "CSAFPID-0003"
                                        }
                                    }
                                ],
                                "name": "18.0",
                                "category": "product_version"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=19.0.0.1|<=19.0.0.12",
                                        "product": {
                                            "name": "IBM WebSphere Application Server Liberty 19.0 vers:vrmf/>=19.0.0.1|<=19.0.0.12",
                                            "product_id": "CSAFPID-0004"
                                        }
                                    }
                                ],
                                "name": "19.0",
                                "category": "product_version"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=20.0.0.1|<=20.0.0.12",
                                        "product": {
                                            "name": "IBM WebSphere Application Server Liberty 20.0 vers:vrmf/>=20.0.0.1|<=20.0.0.12",
                                            "product_id": "CSAFPID-0005"
                                        }
                                    }
                                ],
                                "name": "20.0",
                                "category": "product_version"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=21.0.0.1|<=21.0.0.12",
                                        "product": {
                                            "name": "IBM WebSphere Application Server Liberty 21.0 vers:vrmf/>=21.0.0.1|<=21.0.0.12",
                                            "product_id": "CSAFPID-0006"
                                        }
                                    }
                                ],
                                "name": "21.0",
                                "category": "product_version"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=22.0.0.1|<=22.0.0.13",
                                        "product": {
                                            "name": "IBM WebSphere Application Server Liberty 22.0 vers:vrmf/>=22.0.0.1|<=22.0.0.13",
                                            "product_id": "CSAFPID-0007"
                                        }
                                    }
                                ],
                                "name": "22.0",
                                "category": "product_version"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=23.0.0.1|<=23.0.0.12",
                                        "product": {
                                            "name": "IBM WebSphere Application Server Liberty 23.0 vers:vrmf/>=23.0.0.1|<=23.0.0.12",
                                            "product_id": "CSAFPID-0008"
                                        }
                                    }
                                ],
                                "name": "23.0",
                                "category": "product_version"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=24.0.0.1|<=24.0.0.12",
                                        "product": {
                                            "name": "IBM WebSphere Application Server Liberty 24.0 vers:vrmf/>=24.0.0.1|<=24.0.0.12",
                                            "product_id": "CSAFPID-0009"
                                        }
                                    }
                                ],
                                "name": "24.0",
                                "category": "product_version"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=25.0.0.1|<=25.0.0.12",
                                        "product": {
                                            "name": "IBM WebSphere Application Server Liberty 25.0 vers:vrmf/>=25.0.0.1|<=25.0.0.12",
                                            "product_id": "CSAFPID-0010"
                                        }
                                    }
                                ],
                                "name": "25.0",
                                "category": "product_version"
                            },
                            {
                                "category": "patch_level",
                                "name": "26.0.0.9",
                                "product": {
                                    "name": "IBM WebSphere Application Server Liberty 26.0.0.9",
                                    "product_id": "CSAFPID-0017"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "WebSphere Application Server Liberty"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:vrmf/>=9.0.0.0|<=9.0.5.28",
                                        "product": {
                                            "name": "IBM WebSphere Application Server 9.0 vers:vrmf/>=9.0.0.0|<=9.0.5.28",
                                            "product_id": "CSAFPID-0018"
                                        }
                                    },
                                    {
                                        "category": "patch_level",
                                        "name": "9.0.5.29",
                                        "product": {
                                            "name": "IBM WebSphere Application Server 9.0.5.29",
                                            "product_id": "CSAFPID-0020"
                                        }
                                    }
                                ],
                                "name": "9.0",
                                "category": "product_version"
                            }
                        ],
                        "category": "product_name",
                        "name": "WebSphere Application Server"
                    }
                ],
                "category": "vendor",
                "name": "IBM"
            }
        ],
        "full_product_names": [
            {
                "name": "xmlWS-3.0",
                "product_id": "CSAFPID-0011"
            },
            {
                "name": "jaxws-2.2",
                "product_id": "CSAFPID-0012"
            },
            {
                "name": "jaxrs-2.0",
                "product_id": "CSAFPID-0013"
            },
            {
                "name": "xmlWS-4.0",
                "product_id": "CSAFPID-0014"
            },
            {
                "name": "jaxrs-2.1",
                "product_id": "CSAFPID-0015"
            },
            {
                "name": "z/OS",
                "product_id": "CSAFPID-0021"
            },
            {
                "name": "Mac OS",
                "product_id": "CSAFPID-0022"
            },
            {
                "name": "Windows",
                "product_id": "CSAFPID-0023"
            },
            {
                "name": "Linux",
                "product_id": "CSAFPID-0024"
            },
            {
                "name": "AIX",
                "product_id": "CSAFPID-0025"
            },
            {
                "name": "IBM i",
                "product_id": "CSAFPID-0026"
            },
            {
                "name": "DT496328",
                "product_id": "CSAFPID-0016"
            },
            {
                "name": "DT496327",
                "product_id": "CSAFPID-0019"
            }
        ],
        "product_groups": [
            {
                "group_id": "CSAFGID-0001",
                "product_ids": [
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023",
                    "CSAFPID-0024",
                    "CSAFPID-0025",
                    "CSAFPID-0026"
                ],
                "summary": "Operating Systems"
            },
            {
                "group_id": "CSAFGID-0002",
                "product_ids": [
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015"
                ],
                "summary": "IBM WebSphere Application Server Liberty Features"
            },
            {
                "group_id": "CSAFGID-0003",
                "product_ids": [
                    "CSAFPID-0016",
                    "CSAFPID-0019"
                ],
                "summary": "Security Bulletin APARs"
            }
        ],
        "relationships": [
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server Liberty 26.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0027"
                },
                "product_reference": "CSAFPID-0016",
                "relates_to_product_reference": "CSAFPID-0001"
            },
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server Liberty 17.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0028"
                },
                "product_reference": "CSAFPID-0016",
                "relates_to_product_reference": "CSAFPID-0002"
            },
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server Liberty 18.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0029"
                },
                "product_reference": "CSAFPID-0016",
                "relates_to_product_reference": "CSAFPID-0003"
            },
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server Liberty 19.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0030"
                },
                "product_reference": "CSAFPID-0016",
                "relates_to_product_reference": "CSAFPID-0004"
            },
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server Liberty 20.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0031"
                },
                "product_reference": "CSAFPID-0016",
                "relates_to_product_reference": "CSAFPID-0005"
            },
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server Liberty 21.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0032"
                },
                "product_reference": "CSAFPID-0016",
                "relates_to_product_reference": "CSAFPID-0006"
            },
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server Liberty 22.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0033"
                },
                "product_reference": "CSAFPID-0016",
                "relates_to_product_reference": "CSAFPID-0007"
            },
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server Liberty 23.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0034"
                },
                "product_reference": "CSAFPID-0016",
                "relates_to_product_reference": "CSAFPID-0008"
            },
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server Liberty 24.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0035"
                },
                "product_reference": "CSAFPID-0016",
                "relates_to_product_reference": "CSAFPID-0009"
            },
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server Liberty 25.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0036"
                },
                "product_reference": "CSAFPID-0016",
                "relates_to_product_reference": "CSAFPID-0010"
            },
            {
                "category": "installed_on",
                "full_product_name": {
                    "name": "IBM WebSphere Application Server 9.0 APAR Remediation Action",
                    "product_id": "CSAFPID-0037"
                },
                "product_reference": "CSAFPID-0019",
                "relates_to_product_reference": "CSAFPID-0018"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-57819",
            "notes": [
                {
                    "category": "description",
                    "text": "Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the maxFormParameterCount configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default limit of 500 parameters."
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-0017",
                    "CSAFPID-0020"
                ],
                "known_affected": [
                    "CSAFPID-0018",
                    "CSAFPID-0009",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0002",
                    "CSAFPID-0001",
                    "CSAFPID-0008",
                    "CSAFPID-0010"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Complete CVSS v3 Guide",
                    "url": "https://www.first.org/cvss/user-guide"
                },
                {
                    "category": "external",
                    "summary": "On-line Calculator v3",
                    "url": "https://www.first.org/cvss/calculator/3.0"
                },
                {
                    "category": "external",
                    "summary": "Complete CVSS v4 Guide",
                    "url": "https://www.first.org/cvss/user-guide"
                },
                {
                    "category": "external",
                    "summary": "On-line Calculator v4",
                    "url": "https://www.first.org/cvss/calculator/4.0"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496328",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0008",
                        "CSAFPID-0010",
                        "CSAFPID-0003",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0002",
                        "CSAFPID-0001",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Apply Fix Pack 26.0.0.9 or later (targeted availability 3Q2026).",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0008",
                        "CSAFPID-0010",
                        "CSAFPID-0003",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0002",
                        "CSAFPID-0001",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496327",
                    "product_ids": [
                        "CSAFPID-0018"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).",
                    "product_ids": [
                        "CSAFPID-0018"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "HIGH",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "NONE",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0018",
                        "CSAFPID-0009",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0002",
                        "CSAFPID-0001",
                        "CSAFPID-0008",
                        "CSAFPID-0010"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-54225",
            "notes": [
                {
                    "category": "description",
                    "text": "Apache CXF allows to control the maximum attachment size via the attachment-max-size. Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a default attachment size limit of 50mb."
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-0017",
                    "CSAFPID-0020"
                ],
                "known_affected": [
                    "CSAFPID-0018",
                    "CSAFPID-0009",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0002",
                    "CSAFPID-0001",
                    "CSAFPID-0008",
                    "CSAFPID-0010"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Complete CVSS v3 Guide",
                    "url": "https://www.first.org/cvss/user-guide"
                },
                {
                    "category": "external",
                    "summary": "On-line Calculator v3",
                    "url": "https://www.first.org/cvss/calculator/3.0"
                },
                {
                    "category": "external",
                    "summary": "Complete CVSS v4 Guide",
                    "url": "https://www.first.org/cvss/user-guide"
                },
                {
                    "category": "external",
                    "summary": "On-line Calculator v4",
                    "url": "https://www.first.org/cvss/calculator/4.0"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496328",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0008",
                        "CSAFPID-0010",
                        "CSAFPID-0003",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0002",
                        "CSAFPID-0001",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Apply Fix Pack 26.0.0.9 or later (targeted availability 3Q2026).",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0008",
                        "CSAFPID-0010",
                        "CSAFPID-0003",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0002",
                        "CSAFPID-0001",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496327",
                    "product_ids": [
                        "CSAFPID-0018"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).",
                    "product_ids": [
                        "CSAFPID-0018"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "HIGH",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "NONE",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0018",
                        "CSAFPID-0009",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0002",
                        "CSAFPID-0001",
                        "CSAFPID-0008",
                        "CSAFPID-0010"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-64958",
            "notes": [
                {
                    "category": "description",
                    "text": "An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue."
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-0017",
                    "CSAFPID-0020"
                ],
                "known_affected": [
                    "CSAFPID-0018",
                    "CSAFPID-0009",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0002",
                    "CSAFPID-0001",
                    "CSAFPID-0008",
                    "CSAFPID-0010"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Complete CVSS v3 Guide",
                    "url": "https://www.first.org/cvss/user-guide"
                },
                {
                    "category": "external",
                    "summary": "On-line Calculator v3",
                    "url": "https://www.first.org/cvss/calculator/3.0"
                },
                {
                    "category": "external",
                    "summary": "Complete CVSS v4 Guide",
                    "url": "https://www.first.org/cvss/user-guide"
                },
                {
                    "category": "external",
                    "summary": "On-line Calculator v4",
                    "url": "https://www.first.org/cvss/calculator/4.0"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496328",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0008",
                        "CSAFPID-0010",
                        "CSAFPID-0003",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0002",
                        "CSAFPID-0001",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Apply Fix Pack 26.0.0.9 or later (targeted availability 3Q2026).",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0008",
                        "CSAFPID-0010",
                        "CSAFPID-0003",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0002",
                        "CSAFPID-0001",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496327",
                    "product_ids": [
                        "CSAFPID-0018"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).",
                    "product_ids": [
                        "CSAFPID-0018"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "HIGH",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "NONE",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0018",
                        "CSAFPID-0009",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0002",
                        "CSAFPID-0001",
                        "CSAFPID-0008",
                        "CSAFPID-0010"
                    ]
                }
            ]
        }
    ]
}