CVE-2026-11595: IBM WebSphere Application Server is affected by a Path Traversal vulnerability
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.
Other sources
IBM WebSphere Application Server could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29 - Compensating control
Apply the currently available interim fix or fix pack that contains the fix for APAR PH71756, and carefully follow the additional post-installation instructions provided in the interim fix link referenced for PH71756.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11595?
The severity of CVE-2026-11595 is rated medium with a score of 4.3.
How can I mitigate the risk of CVE-2026-11595?
To mitigate CVE-2026-11595, ensure that the IBM WebSphere Application Server is updated to a patched version that addresses the Path Traversal vulnerability.
What systems are affected by CVE-2026-11595?
CVE-2026-11595 affects IBM WebSphere Application Server versions 9.0 and 8.5.
What vulnerability type is CVE-2026-11595 classified as?
CVE-2026-11595 is classified as a Path Traversal vulnerability.
What type of information could be leaked due to CVE-2026-11595?
CVE-2026-11595 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.