Description
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
Published: 2026-07-28
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM WebSphere Application Server versions 8.5 and 9.0 (traditional edition) contain a flaw that enables remote attackers to inject malicious scripts into web responses viewed in clients’ browsers. The vulnerability is an instance of Cross‑Site Scripting (CWE‑79) and can result in the compromise of session data, credential theft, and defacement of web pages. The advisory title also mentions deserialization, but no explicit impact or detailed description of that aspect is provided in the CVE data, so no assumptions about code execution can be made.

Affected Systems

The vulnerability affects IBM WebSphere Application Server traditional editions in the following version ranges: 8.5.0.0 through 8.5.5.30 and 9.0.0.0 through 9.0.5.28. Only installations running the traditional release line are impacted; other variants or later application server versions are not listed as affected.

Risk and Exploitability

The CVSS score of 6.1 indicates a Medium severity and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Attackers can exploit the issue remotely over the public network by sending crafted requests that result in malicious script being returned to a victim’s browser. The client‑side nature of the exploit means that the threat primarily arises when a user interacts with the compromised web interface.

Generated by OpenCVE AI on August 4, 2026 at 23:27 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR DT496118. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496118 https://www.ibm.com/support/pages/node/7280369 --OR-- · Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).  For V8.5.0.0 through 8.5.5.30: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496118 https://www.ibm.com/support/pages/node/7280369 --OR-- · Apply Fix Pack 8.5.5.31 or later (targeted availability 3Q2026).  Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Apply the interim fix DT496118 after upgrading to the minimal required fix‑pack level for your version.
  • Upgrade to Fix Pack 8.5.5.31 (or later) for 8.5 deployments, or Fix Pack 9.0.5.29 (or later) for 9.0 deployments, once available.
  • If the interim or targeted fix is unavailable, download and install additional interim fixes linked from the IBM support page for WebSphere Application Server.

Generated by OpenCVE AI on August 4, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
Title IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-29T12:39:03.143Z

Reserved: 2026-07-02T19:23:18.880Z

Link: CVE-2026-14515

cve-icon Vulnrichment

Updated: 2026-07-29T12:38:56.690Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T21:17:25.923

Modified: 2026-08-05T16:21:39.630

Link: CVE-2026-14515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:30:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')