CVE 5.4 MEDIUM

IBM WebSphere Application Server and WebSphere Application Server Liberty Cross-Site Scripting_CVE-2025-12635

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Description

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious site.

Basic Information

ID CVE-2025-12635
Source ibm
Published Dec 8, 2025 at 21:58

Affected Product

Vendor IBM
Product WebSphere Application Server
Version 9.0
Affected Versions IBM WebSphere Application Server 9.0
IBM WebSphere Application Server 8.5
IBM WebSphere Application Server Liberty 17.0.0.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.