CVE-2026-11712: IBM WebSphere Application Server is affected by a cross-site scripting vulnerability
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
Other sources
IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console help system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional (administrative console help system)to a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditional (administrative console help system)to a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71756
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11712?
CVE-2026-11712 has a critical severity rating of 9.3.
How do I fix CVE-2026-11712?
To fix CVE-2026-11712, apply the latest security patches provided by IBM for WebSphere Application Server versions 8.5 and 9.0.
What type of vulnerability is CVE-2026-11712?
CVE-2026-11712 is classified as a cross-site scripting (XSS) vulnerability.
What versions of IBM WebSphere Application Server are affected by CVE-2026-11712?
CVE-2026-11712 affects IBM WebSphere Application Server versions 9.0 and 8.5.
What impact does CVE-2026-11712 have on security?
CVE-2026-11712 can lead to unauthorized access and data exposure due to XSS vulnerabilities in the administrative console help system.