CVE-2026-15412: IBM WebSphere Application Server vulnerability
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to persuade a victim to visit a specially crafted website. Exploitation relies on redirecting the victim to a malicious site while making it appear trusted.
Who is directly targeted by this vulnerability?
The direct target is a user who can be lured into following the crafted link or visiting the attacker-controlled website. The attacker may then seek sensitive information from that victim or use the redirect as part of further attacks.