
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12635 is a cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) and WebSphere Application Server Liberty caused by improper validation of user-supplied input. Affected versions include IBM WebSphere Application Server 8.5 (before 8.5.5.29) and 9.0 (before 9.0.5.27), and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 (before 26.0.0.1). The vulnerability was published on December 8, 2025, and patches have since been extended to numerous downstream IBM products. It carries a CVSS v3.1 base score of 5.4 (Medium) (IBM Advisory, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). An attacker with low-privilege network access can craft a specially crafted URL that, when followed by a victim user, causes the application to redirect them to a malicious site or execute attacker-controlled script in the victim's browser context. Exploitation requires user interaction (the victim must follow or be tricked into visiting the crafted URL), and the scope is changed, meaning the impact can extend beyond the vulnerable component itself. No public proof-of-concept code has been identified (IBM Advisory, Red Hat CVE).
Successful exploitation can result in low-level confidentiality and integrity impacts — specifically, theft of session cookies or credentials, redirection of users to phishing or malware-hosting sites, manipulation of displayed web content, and potential session hijacking. Because the vulnerability's scope is marked as "Changed," the attacker's malicious script executes in the context of the victim's browser session, potentially affecting resources beyond the WAS application itself. Availability is not directly impacted (IBM Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat CVE).
Location: headers pointing to external sites.%3Cscript%3E, javascript:, data:) or suspicious redirect parameters in query strings; error logs indicating unexpected URL parsing activity.IBM has released patched versions addressing this vulnerability: WebSphere Application Server 8.5.5.29 or later, WebSphere Application Server 9.0.5.27 or later, and WebSphere Application Server Liberty 26.0.0.1 or later. Patches have also been issued for numerous downstream IBM products including CICS Transaction Gateway, IBM Cloud Pak for Business Automation, IBM Business Automation Workflow, IBM Application Performance Management, IBM PowerVM Novalink, IBM Security Verify Access, and IBM Business Automation Insights. As interim mitigations, organizations should implement strict input validation, deploy Web Application Firewall (WAF) rules to detect XSS patterns, enforce Content Security Policy (CSP) headers, and monitor for suspicious URL redirects (IBM Advisory, IBM APM Advisory, IBM Verify Access Advisory).
Coverage of CVE-2025-12635 has been primarily technical and advisory-focused, with security news outlets such as GBHackers, CyberSecurityNews, and Cybernoz reporting on the broader IBM Security Verify Access vulnerability disclosures that include this CVE. IBM has issued multiple security bulletins across its product portfolio acknowledging the issue and providing remediation guidance. No significant independent researcher commentary or social media controversy has been observed beyond routine vulnerability tracking (GBHackers, CyberSecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."