Cross-Site Scripting Vulnerability in IBM WebSphere Application Server
CVE-2025-12635
5.4MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 8 December 2025
What is CVE-2025-12635?
IBM WebSphere Application Server versions 8.5 and 9.0, along with WebSphere Application Server Liberty versions 17.0.0.3 to 25.0.0.12, are vulnerable to cross-site scripting due to inadequate validation of user input. This flaw allows attackers to craft malicious URLs that, when accessed, can redirect users to harmful sites, potentially leading to unauthorized access to sensitive information or systems.
Affected Version(s)
WebSphere Application Server 9.0 <= 2.0.18
WebSphere Application Server 8.5
WebSphere Application Server Liberty 17.0.0.3 <= 25.0.0.12