CVE-2026-11708: IBM WebSphere Application Server is affected by a cross-site scripting vulnerability
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
Other sources
IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71756
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11708?
CVE-2026-11708 has a critical severity score of 9.3 on the CVSS scale.
How do I fix CVE-2026-11708?
To fix CVE-2026-11708, apply the patches provided by IBM for WebSphere Application Server 9.0 and 8.5.
What systems are affected by CVE-2026-11708?
CVE-2026-11708 affects IBM WebSphere Application Server versions 9.0 and 8.5.
What type of vulnerability is CVE-2026-11708?
CVE-2026-11708 is classified as a cross-site scripting (XSS) vulnerability.
How can CVE-2026-11708 impact users?
CVE-2026-11708 can allow attackers to execute malicious scripts in the context of the user's session through the administrative console's help system.