CVE-2026-11594: IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.
Other sources
IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.30Patch PH71757 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29Patch PH71757
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11594?
The severity of CVE-2026-11594 is rated as high with a score of 8.5.
What types of vulnerabilities are associated with CVE-2026-11594?
CVE-2026-11594 is associated with multiple cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2026-11594?
To fix CVE-2026-11594, apply the latest patches and updates provided by IBM for WebSphere Application Server.
Which versions of IBM WebSphere Application Server are affected by CVE-2026-11594?
IBM WebSphere Application Server versions 9.0 and 8.5 are affected by CVE-2026-11594.
What is the potential impact of CVE-2026-11594?
The potential impact of CVE-2026-11594 includes unauthorized access and manipulation of sensitive information through XSS attacks.