CVE-2026-11545: IBM WebSphere Application Server is affected by a privilege escalation
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.
Other sources
IBM WebSphere Application Server could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.31Patch APAR DT496500 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29Patch APAR DT496500
Event History
Frequently Asked Questions
Which WebSphere Application Server versions are identified as affected?
The affected versions identified are IBM WebSphere Application Server 8.5 and 9.0.
Does an attacker need credentials or user interaction to exploit this issue?
The CVSS vector indicates no privileges and no user interaction are required. Exploitation is remote, but has high attack complexity.
What is the stated security impact?
A successful attacker could obtain sensitive information from the administrative console. The reported impact is limited to confidentiality; integrity and availability impacts are not identified.