Multiple vulnerabilities in IBM WebSphere Application Server, including remote code execution and cross-site scripting flaws, could be exploited by a remote attacker. Affected versions include WebSphere Application Server 8.5, 9.0, and Liberty from versions 17.0.0.3 through 26.0.0.6. IBM has provided specific fixes; administrators must apply the patches from the provided vendor links as no workarounds are detailed.
Multiple vulnerabilities were identified in IBM WebSphere Products. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting and remote code execution on the targeted system. Impact Remote Code Execution Cross-Site Scripting System / Technologies affected IBM WebSphere Application Server - 8.5 IBM WebSphere Application Server - 9.0 IBM WebSphere Application Server - Liberty - 17.0.0.3 - 26.0.0.6 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://www.ibm.com/support/pages/node/7277544 https://www.ibm.com/support/pages/node/7277546 https://www.ibm.com/support/pages/node/7277550