Executive brief
IBM WebSphere Application Server, a platform used to host and manage enterprise Java applications, is affected by a security vulnerability in its administrative console. An attacker could use this flaw to execute malicious scripts in the browser of a legitimate administrator who visits a compromised link. This could lead to unauthorized access to the management interface, potentially allowing the attacker to modify server configurations or access sensitive application data.
Technical details
A cross-site scripting (XSS) vulnerability exists in the administrative console of IBM WebSphere Application Server versions 9.0 and 8.5. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An attacker can exploit this by persuading a user with access to the administrative console to click a specially crafted link. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser session, which can lead to session hijacking or unauthorized administrative actions. IBM has released interim fix PH71757 and plans to include the fix in upcoming fix packs 9.0.5.29 and 8.5.5.30.
Affected products
- IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.29
Timeline
- 2026-06-23: disclosed: Initial publication by IBM
- 2026-06-30: advisory: NVD publication date