Open Redirect Vulnerability in IBM WebSphere Application Server
CVE-2026-15412

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 September 2026

What is CVE-2026-15412?

IBM WebSphere Application Server versions 9.0, 8.5, and the Liberty edition are susceptible to an open redirect vulnerability. This flaw can be exploited by remote attackers to launch phishing attacks. By enticing victims to access a specially crafted URL, attackers can manipulate the webpage to misrepresent the real destination, effectively spoofing a trusted URL. This manipulation can lead users to malicious websites designed to capture sensitive information or facilitate further attacks.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.