Impact
The vulnerability is a reflected cross‑site scripting (XSS) flaw that allows an attacker to embed malicious script code into reflected inputs. When such input is rendered by a victim’s browser, the script runs in the context of the victim’s session, potentially leading to unauthorized access, session hijacking, or phishing. This weakness is identified as CWE‑79 and primarily affects client‑side integrity and confidentiality.
Affected Systems
IBM WebSphere Application Server 8.5.0.0 through 8.5.5.30 and 9.0.0.0 through 9.0.5.28 are affected. IBM recommends applying Fix Pack 8.5.5.31 or a later update for the 8.5 series and Fix Pack 9.0.5.29 (SB0030823) or later for the 9.0 series to remediate the vulnerability.
Risk and Exploitability
With a CVSS score of 5.4 the vulnerability is considered moderate. The EPSS score is not available and the issue is not listed in CISA KEV. Exploitation requires a crafted URL or input that is reflected back to the user, meaning a user interaction (the victim must click a malicious link or submit input) is needed. Once executed, the attacker gains the victim’s browser context but cannot directly compromise the server. The overall threat remains moderate until the vendor’s fix pack is deployed.
OpenCVE Enrichment