Junglewise Threat Intelligence

CVE-2026-14515: IBM WebSphere Application Server cross-site scripting

CVE-2026-14515 · Severity: medium · CVSS 6.1 · Published 2026-07-28

Vendors: IBM.

Executive brief

IBM WebSphere Application Server, a platform used to host and run enterprise Java applications, is vulnerable to a security flaw that could allow an attacker to execute malicious scripts in a user's browser. By tricking a user into clicking a malicious link or visiting a compromised page, an attacker could potentially steal session information or perform actions on behalf of the user. This could lead to unauthorized access to sensitive business data or administrative functions within the application environment.

Technical details

A cross-site scripting (XSS) vulnerability exists in IBM WebSphere Application Server traditional versions 8.5 and 9.0. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). A remote, unauthenticated attacker can exploit this by sending a specially crafted URL to a victim, requiring user interaction to trigger the script execution. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or credential theft. IBM has released interim fixes for APAR DT496118 and plans to include the fix in upcoming Fix Packs 8.5.5.31 and 9.0.5.29.

Affected products

  • IBM WebSphere Application Server traditional 8.5.0.0 - 8.5.5.30, 9.0.0.0 - 9.0.5.28

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: patched: Interim fix available; Fix Packs scheduled for 3Q2026

References