Information Disclosure Vulnerability in IBM WebSphere Application Server
CVE-2026-11537

4.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2026-11537?

IBM WebSphere Application Server versions 9.0 and 8.5 contain a vulnerability that can be exploited by a remote attacker, potentially allowing unauthorized access to sensitive information about the file system through the FileTransfer servlet. This flaw underscores the importance of timely security updates and robust configuration practices to safeguard sensitive data.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.