CVE-2026-11537: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
Other sources
IBM WebSphere Application Server could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional (FileTransfer servlet)to a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditional (FileTransfer servlet)to a version that resolves this vulnerability.Fixed in 9.0.5.29Patch SB0030823
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The issue is described as exploitable by a remote attacker. No authentication requirement or other prerequisite is provided in the available data.
What information could be exposed?
A successful attack could disclose sensitive information about the underlying file system through the FileTransfer servlet.