CVE-2026-11537: IBM WebSphere Application Server vulnerability
Published Sep 8, 2026
·Updated
IBM WebSphere Application Server could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
Affected Software
2 affected components
IBM WebSphere Application Server<=9.0
IBM WebSphere Application Server<=8.5
Event History
Sep 8, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as exploitable by a remote attacker. No authentication requirement or other prerequisite is provided in the available data.
2
What information could be exposed?
A successful attack could disclose sensitive information about the underlying file system through the FileTransfer servlet.