CVE-2025-12635: IBM WebSphere Application Server and WebSphere Application Server Liberty Cross-Site Scripting
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious site.
Other sources
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious site.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 17.0.0.3 - 25.0.0.12Patch PH68817 - Upgrade
Upgrade
IBM WebSphere Application Server traditional (v9.0.0.0 - 9.0.5.26)to a version that resolves this vulnerability.Fixed in 9.0.5.27 or laterPatch PH68243 - Upgrade
Upgrade
IBM WebSphere Application Server traditional (v8.5.0.0 - 8.5.5.28)to a version that resolves this vulnerability.Fixed in 8.5.5.29 or laterPatch PH68243
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12635?
CVE-2025-12635 has a moderate severity level due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2025-12635?
To fix CVE-2025-12635, ensure that you apply the latest security updates provided by IBM for WebSphere Application Server and its Liberty variant.
Which versions of IBM WebSphere are affected by CVE-2025-12635?
CVE-2025-12635 affects IBM WebSphere Application Server versions up to 9.0 and IBM WebSphere Application Server Liberty from 17.0.0.3 to 25.0.0.12.
Can CVE-2025-12635 lead to data leakage?
Yes, if exploited, CVE-2025-12635 could potentially lead to data leakage through cross-site scripting attacks.
What type of vulnerability is CVE-2025-12635?
CVE-2025-12635 is classified as a cross-site scripting (XSS) vulnerability due to improper validation of user-supplied input.