Description
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.
Published: 2026-06-30
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw in the administrative console, classified under CWE-79. By inserting malicious script into administrative pages, an attacker can cause arbitrary JavaScript to execute within a user’s browser that accesses the console, potentially leading to data theft, session hijacking, or impersonation of privileged users. The flaw does not expose system information directly, but it can be leveraged to perform actions on behalf of the authenticated console user.

Affected Systems

IBM WebSphere Application Server versions 8.5 and 9.0 are affected. For V9.0.0.0 through 9.0.5.28 the recommended fix is to upgrade to the minimal required fix‑pack levels, then apply the interim fix PH71757, or to install Fix Pack 9.0.5.29 or a later release. For V8.5.0.0 through 8.5.5.29 the same process applies: upgrade to the minimal required fix‑pack, then apply PH71757, or install Fix Pack 8.5.5.30 or later.

Risk and Exploitability

With a CVSS score of 8.5 this flaw is considered high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the administrative console, where an attacker with the ability to submit input can embed malicious scripts. If successfully exploited, the attacker can execute code in the browser context of any user who interacts with the compromised console. The risk is further heightened if the console is exposed to external networks. Maintaining the latest fix packs reduces exploitability, but any unpatched system remains vulnerable until the interim fix or subsequent fix pack is applied.

Generated by OpenCVE AI on June 30, 2026 at 22:51 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH71757. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH71757 https://www.ibm.com/support/pages/node/7277464 --OR-- · Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).  For V8.5.0.0 through 8.5.5.29: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH71757 https://www.ibm.com/support/pages/node/7277464 --OR-- · Apply Fix Pack 8.5.5.30 or later (targeted availability 3Q2026).  Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Download and apply the interim fix PH71757 from the IBM support page dedicated to this issue.
  • Upgrade to the latest supported fix pack: for WebSphere 9.0 install 9.0.5.29 or newer, for 8.5 install 8.5.5.30 or newer, ensuring all servers run the updated pack.
  • Restrict access to the WebSphere administrative console to trusted users or networks by configuring firewall rules or VPN access to reduce exposure.

Generated by OpenCVE AI on June 30, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.
Title IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-01T14:29:19.691Z

Reserved: 2026-06-08T14:06:40.450Z

Link: CVE-2026-11594

cve-icon Vulnrichment

Updated: 2026-07-01T13:49:07.020Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T05:45:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')