Executive brief
IBM WebSphere Application Server, a platform used to build and run enterprise applications, is affected by a security flaw in its administrative console's help system. An attacker could use this vulnerability to execute malicious scripts in a user's browser, potentially leading to unauthorized actions or the theft of sensitive administrative session information. Organizations should apply the available interim fixes or upgrade to the latest fix pack to protect their management interfaces.
Technical details
A cross-site scripting (XSS) vulnerability exists in the integrated help system of the IBM WebSphere Application Server administrative console. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link, allowing the execution of arbitrary JavaScript in the context of the victim's browser session. This can lead to session hijacking or unauthorized administrative actions. The vulnerability affects versions 9.0 (up to 9.0.5.28) and 8.5 (up to 8.5.5.30), and can be remediated by applying interim fix PH71756 or upgrading to fix packs 9.0.5.29 / 8.5.5.31.
Affected products
- IBM WebSphere Application Server 9.0.0.0 through 9.0.5.28, 8.5.0.0 through 8.5.5.30
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory
- 2026-06-30: patched