Junglewise Threat Intelligence

CVE-2026-11595: IBM WebSphere Application Server path traversal in administrative console help system

CVE-2026-11595 · Severity: medium · CVSS 4.3 · Published 2026-06-30

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server, a platform used for hosting enterprise Java applications, contains a security flaw in its administrative console's help system. An attacker on the same local network could exploit this to access sensitive information that should otherwise be restricted. This could lead to the exposure of internal configuration details or system files, potentially aiding further attacks against the organization's infrastructure.

Technical details

A path traversal vulnerability (CWE-22) exists in the integrated help system of the IBM WebSphere Application Server administrative console. The flaw is caused by improper limitation of a pathname to a restricted directory, allowing a remote attacker with adjacent network access to bypass security restrictions. By sending a specially crafted request, an attacker can read arbitrary files or sensitive information from the server's file system. The vulnerability affects versions 9.0 and 8.5 and is addressed by applying interim fix PH71756 or upgrading to fix packs 9.0.5.29 and 8.5.5.31 respectively.

Affected products

  • IBM WebSphere Application Server 9.0.0.0 through 9.0.5.28, 8.5.0.0 through 8.5.5.30

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory
  • 2026-06-30: patched: Interim fix PH71756 released

References

Related threats