5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Description
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious site.
Basic Information
ID
CVE-2025-12635
Source
ibm
Published
Dec 8, 2025 at 21:58
Affected Product
Vendor
IBM
Product
WebSphere Application Server
Version
9.0
Affected Versions
IBM WebSphere Application Server 9.0
IBM WebSphere Application Server 8.5
IBM WebSphere Application Server Liberty 17.0.0.3
IBM WebSphere Application Server 8.5
IBM WebSphere Application Server Liberty 17.0.0.3