CVE-2025-33104: IBM WebSphere Application Server cross
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33104?
CVE-2025-33104 is considered a high severity vulnerability due to its potential to allow cross-site scripting attacks.
What types of software are affected by CVE-2025-33104?
CVE-2025-33104 affects IBM WebSphere Application Server versions 8.5 and 9.0.
How do I fix CVE-2025-33104?
To mitigate CVE-2025-33104, users should apply the latest security patches provided by IBM for the affected versions.
What are the potential risks of CVE-2025-33104?
Exploitation of CVE-2025-33104 may lead to unauthorized access, alteration of the web UI, and potential disclosure of user credentials.
What is cross-site scripting in the context of CVE-2025-33104?
In the context of CVE-2025-33104, cross-site scripting allows attackers to embed malicious JavaScript code in the web application's user interface.