Junglewise Threat Intelligence

CVE-2026-11537: IBM WebSphere Application Server information disclosure via FileTransfer servlet

CVE-2026-11537 · Severity: medium · CVSS 4.3 · Published 2026-09-18

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server is a Java application platform used to host enterprise web applications and services. A remote attacker can exploit a vulnerability in the FileTransfer servlet to obtain sensitive information about the server's file system, potentially exposing configuration files, source code, or other confidential data.

Technical details

The vulnerability exists in the FileTransfer servlet of IBM WebSphere Application Server versions 8.5 and 9.0 prior to the patched versions (8.5.5.31 and 9.0.5.29). A remote attacker can leverage improper access controls or input validation in this servlet to read files from the server's file system. The attack requires network access to the vulnerable servlet and no authentication is specified as required.

Affected products

  • IBM WebSphere Application Server 8.5 before 8.5.5.31, 9.0 before 9.0.5.29

Timeline

  • 2026-09-18: disclosed

References

Related threats