Cross-Site Scripting Vulnerability in IBM WebSphere Application Server
CVE-2025-12635

5.4MEDIUM

What is CVE-2025-12635?

IBM WebSphere Application Server versions 8.5 and 9.0, along with WebSphere Application Server Liberty versions 17.0.0.3 to 25.0.0.12, are vulnerable to cross-site scripting due to inadequate validation of user input. This flaw allows attackers to craft malicious URLs that, when accessed, can redirect users to harmful sites, potentially leading to unauthorized access to sensitive information or systems.

Affected Version(s)

WebSphere Application Server 9.0 <= 2.0.18

WebSphere Application Server 8.5

WebSphere Application Server Liberty 17.0.0.3 <= 25.0.0.12

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-12635 : Cross-Site Scripting Vulnerability in IBM WebSphere Application Server