
Cloud Vulnerability DB
A community-led vulnerabilities database
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting (XSS). The vulnerability was discovered and disclosed in June 2024, affecting versions 8.5.0.0 through 8.5.5.25 and 9.0.0.0 through 9.0.5.20. This security issue was assigned CVE-2024-35153 with IBM X-Force ID: 292640 (IBM Advisory, NVD).
The vulnerability is a cross-site scripting (XSS) issue that exists in the administrative console of WebSphere Application Server. It has been assigned a CVSS v3.1 Base Score of 4.8 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N. The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) (NVD).
This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI, potentially altering the intended functionality. The primary risk is the potential disclosure of credentials within a trusted session (IBM Advisory).
The vulnerability requires a privileged user account to exploit and user interaction is necessary. The attack complexity is considered low, but the privileged access requirement somewhat mitigates the risk (NVD).
IBM recommends addressing the vulnerability by applying currently available interim fix PH61546 or upgrading to newer fix packs. For V9.0.0.0 through 9.0.5.20, users should either apply Interim Fix PH61546 or upgrade to Fix Pack 9.0.5.21 or later (targeted for 3Q2024). For V8.5.0.0 through 8.5.5.25, users should either apply Interim Fix PH61546 or upgrade to Fix Pack 8.5.5.26 or later (targeted for 3Q2024). No workarounds are available (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."