Description
IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected cross‑site scripting
Action: Immediate patch
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting (XSS) flaw that allows an attacker to embed malicious script code into reflected inputs. When such input is rendered by a victim’s browser, the script runs in the context of the victim’s session, potentially leading to unauthorized access, session hijacking, or phishing. This weakness is identified as CWE‑79 and primarily affects client‑side integrity and confidentiality.

Affected Systems

IBM WebSphere Application Server 8.5.0.0 through 8.5.5.30 and 9.0.0.0 through 9.0.5.28 are affected. IBM recommends applying Fix Pack 8.5.5.31 or a later update for the 8.5 series and Fix Pack 9.0.5.29 (SB0030823) or later for the 9.0 series to remediate the vulnerability.

Risk and Exploitability

With a CVSS score of 5.4 the vulnerability is considered moderate. The EPSS score is not available and the issue is not listed in CISA KEV. Exploitation requires a crafted URL or input that is reflected back to the user, meaning a user interaction (the victim must click a malicious link or submit input) is needed. Once executed, the attacker gains the victim’s browser context but cannot directly compromise the server. The overall threat remains moderate until the vendor’s fix pack is deployed.

Generated by OpenCVE AI on September 15, 2026 at 07:42 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply IBM Fix Pack 9.0.5.29 SB0030823 or later to all WebSphere Application Server 9.0 installations.
  • Apply IBM Fix Pack 8.5.5.31 or later to all WebSphere Application Server 8.5 installations.
  • Ensure that all user‑supplied input reflected in HTTP responses is properly encoded or validated to prevent script execution, following secure coding guidelines for XSS mitigation.

Generated by OpenCVE AI on September 15, 2026 at 07:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T14:45:11.937Z

Reserved: 2026-07-18T01:46:41.773Z

Link: CVE-2026-16186

cve-icon Vulnrichment

Updated: 2026-09-15T14:43:41.708Z

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:39.623

Modified: 2026-09-15T15:17:13.487

Link: CVE-2026-16186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T07:45:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')