IBM WebSphere Application Server 8.5, 9.0 and IBM...
Moderate severity
Unreviewed
Published
Dec 9, 2025
to the GitHub Advisory Database
•
Updated Dec 9, 2025
Description
Published by the National Vulnerability Database
Dec 8, 2025
Published to the GitHub Advisory Database
Dec 9, 2025
Last updated
Dec 9, 2025
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious site.
References