Multiple IBM WebSphere Vulnerabilities Enable XSS and Path Traversal Attacks
ID: 7f45eaee-30bf-5fae-ace2-e3e4b65b24e2
STIX ID: report--7f45eaee-30bf-5fae-ace2-e3e4b65b24e2
Feed Name: cybersecurityNews.com
Multiple critical and medium-severity vulnerabilities were disclosed in IBM WebSphere Application Server (8.5 and 9.0) affecting the admin console's integrated help system: two high-severity XSS flaws (CVE-2026-11712, CVE-2026-11708; CVSS 9.3) that can be exploited by luring authenticated administrators to crafted links, and a medium-severity path traversal (CVE-2026-11595; CVSS 4.3) that can expose server files. IBM recommends applying fix packs or interim fixes (APAR PH71756) as no workarounds are provided; teams should prioritize patching and restrict admin console access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
