CVE-2026-11595 – IBM WebSphere Application Server
“Administrative tools deserve the same level of protection as the applications they manage.”
IBM has released security updates for WebSphere Application Server 9.0 and 8.5 to address multiple vulnerabilities affecting the administrative console and its integrated help system. CVE-2026-11712 and CVE-2026-11708 are cross-site scripting (XSS) vulnerabilities (CWE-79) that could allow malicious script execution within the administrative console. CVE-2026-11595 is an information disclosure vulnerability (CWE-22) that could allow a remote attacker to obtain sensitive information from the integrated help system.
CVE-2026-11712 has a CVSS score of 9.3, which is Critical severity. CVE-2026-11708 has a CVSS score of 9.3, which is Critical severity. CVE-2026-11595 has a CVSS score of 4.3, which is Medium severity. Based on the information provided, there is no verified exploitation associated with these vulnerabilities. Organizations running affected WebSphere Application Server versions should apply the available updates to reduce the risk of administrative console compromise and information exposure.
Key Details
- Affected Product
- Ibm Websphere Application Server
- Attack Vector
- Adjacent
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-22