CVE-2026-14515: IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
Other sources
IBM WebSphere Application Server traditional could allow a remote attacker to conduct a cross-site scripting attack.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.31Patch APAR DT496118 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29Patch APAR DT496118 - Compensating control
For IBM WebSphere Application Server traditional, apply a currently available interim fix or fix pack that contains the fix for APAR DT496118 (or apply required minimal fix pack levels and then the Interim Fix that resolves DT496118).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14515?
The severity of CVE-2026-14515 is medium, rated at 6.1.
What vulnerabilities does CVE-2026-14515 address?
CVE-2026-14515 addresses cross-site scripting and deserialization vulnerabilities in IBM WebSphere Application Server.
How can I mitigate the risks associated with CVE-2026-14515?
To mitigate CVE-2026-14515, ensure to apply any available patches and update to the latest version of IBM WebSphere Application Server.
Which versions of IBM WebSphere Application Server are affected by CVE-2026-14515?
CVE-2026-14515 affects IBM WebSphere Application Server versions 8.5 and 9.0 traditional.
Can CVE-2026-14515 lead to remote attacks?
Yes, CVE-2026-14515 can allow remote attackers to conduct cross-site scripting attacks.