Impact
The vulnerability is a cross‑site scripting flaw in the administrative console, classified under CWE-79. By inserting malicious script into administrative pages, an attacker can cause arbitrary JavaScript to execute within a user’s browser that accesses the console, potentially leading to data theft, session hijacking, or impersonation of privileged users. The flaw does not expose system information directly, but it can be leveraged to perform actions on behalf of the authenticated console user.
Affected Systems
IBM WebSphere Application Server versions 8.5 and 9.0 are affected. For V9.0.0.0 through 9.0.5.28 the recommended fix is to upgrade to the minimal required fix‑pack levels, then apply the interim fix PH71757, or to install Fix Pack 9.0.5.29 or a later release. For V8.5.0.0 through 8.5.5.29 the same process applies: upgrade to the minimal required fix‑pack, then apply PH71757, or install Fix Pack 8.5.5.30 or later.
Risk and Exploitability
With a CVSS score of 8.5 this flaw is considered high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the administrative console, where an attacker with the ability to submit input can embed malicious scripts. If successfully exploited, the attacker can execute code in the browser context of any user who interacts with the compromised console. The risk is further heightened if the console is exposed to external networks. Maintaining the latest fix packs reduces exploitability, but any unpatched system remains vulnerable until the interim fix or subsequent fix pack is applied.
OpenCVE Enrichment