IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Subscriptions

Vendors Products
Websphere Application Server Subscribe
Linux Kernel Subscribe
Microsoft Subscribe
Windows Subscribe
Solaris Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14903 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Fixes

Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH66028.


Workaround

No workaround given by the vendor.

History

Wed, 20 Aug 2025 16:00:00 +0000

Type Values Removed Values Added
Title CWE-79 IBM WebSphere Application Server cross

Fri, 18 Jul 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp hp-ux
Ibm aix
Ibm i
Ibm z\/os
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Oracle
Oracle solaris
CPEs cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*
cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:z\/os:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*
Vendors & Products Hp
Hp hp-ux
Ibm aix
Ibm i
Ibm z\/os
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Oracle
Oracle solaris

Wed, 14 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 14 May 2025 19:15:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title CWE-79
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-08-20T15:47:41.244Z

Reserved: 2025-04-15T17:50:40.774Z

Link: CVE-2025-33104

cve-icon Vulnrichment

Updated: 2025-05-14T19:42:21.613Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-14T19:15:53.223

Modified: 2025-07-18T15:56:16.287

Link: CVE-2025-33104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses