Cross-Site Scripting Vulnerability in IBM WebSphere Application Server
CVE-2026-11712

9.3CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 June 2026

What is CVE-2026-11712?

IBM WebSphere Application Server versions 9.0 and 8.5 have been identified as being vulnerable to a cross-site scripting (XSS) issue within the administrative console help system. This vulnerability could be exploited by an attacker to execute arbitrary script code in the context of the user's session, potentially leading to unauthorized actions or data exposure. It is crucial for users to apply the necessary patches provided by IBM to mitigate this risk.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.