---
id: CVE-2025-12635
title: >-
  IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server
  Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to
  improper validation of user-supplied input
summary: >-
  IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server
  Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to
  improper validation of user-supplied input. An attacker could exploit this
  vuln…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: ibm
product: websphere_application_server
affected:
  - 'websphere_application_server >= 8.5, < 8.5.5.29'
  - 'websphere_application_server >= 9.0, < 9.0.5.27'
  - 'websphere_application_server >= 17.0.0.3, < 26.0.0.1'
patched:
  - websphere_application_server 26.0.0.1
published: '2025-12-08'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12635'
references:
  - url: 'https://www.ibm.com/support/pages/node/7254078'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00167
epssPercentile: 0.05424
ingestedAt: '2026-10-07T20:46:46.774Z'
---

## Overview

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious site.

## Affected

- `websphere_application_server >= 8.5, < 8.5.5.29`
- `websphere_application_server >= 9.0, < 9.0.5.27`
- `websphere_application_server >= 17.0.0.3, < 26.0.0.1`

## Remediation

Upgrade past the affected range:

- `websphere_application_server 26.0.0.1`
