CVE-2025-12635
IBM WebSphere Application Server vulnerability analysis and mitigation

Overview

CVE-2025-12635 is a cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) and WebSphere Application Server Liberty caused by improper validation of user-supplied input. Affected versions include IBM WebSphere Application Server 8.5 (before 8.5.5.29) and 9.0 (before 9.0.5.27), and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 (before 26.0.0.1). The vulnerability was published on December 8, 2025, and patches have since been extended to numerous downstream IBM products. It carries a CVSS v3.1 base score of 5.4 (Medium) (IBM Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). An attacker with low-privilege network access can craft a specially crafted URL that, when followed by a victim user, causes the application to redirect them to a malicious site or execute attacker-controlled script in the victim's browser context. Exploitation requires user interaction (the victim must follow or be tricked into visiting the crafted URL), and the scope is changed, meaning the impact can extend beyond the vulnerable component itself. No public proof-of-concept code has been identified (IBM Advisory, Red Hat CVE).

Impact

Successful exploitation can result in low-level confidentiality and integrity impacts — specifically, theft of session cookies or credentials, redirection of users to phishing or malware-hosting sites, manipulation of displayed web content, and potential session hijacking. Because the vulnerability's scope is marked as "Changed," the attacker's malicious script executes in the context of the victim's browser session, potentially affecting resources beyond the WAS application itself. Availability is not directly impacted (IBM Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing IBM WebSphere Application Server (8.5.x before 8.5.5.29, 9.0.x before 9.0.5.27) or Liberty (17.0.0.3–25.0.0.12) instances using tools like Shodan or Censys.
  2. Craft malicious URL: Construct a specially crafted URL targeting a WAS endpoint that reflects user-supplied input without proper sanitization, embedding a malicious script or redirect payload in a URL parameter.
  3. Deliver to victim: Distribute the crafted URL to a target user via phishing email, social engineering, or by embedding it in a web page — exploiting the required user interaction condition.
  4. Achieve XSS/redirect: When the victim clicks the link and their browser processes the response, the injected script executes in the victim's browser context or the user is redirected to a malicious site, enabling credential theft, session hijacking, or malware delivery (IBM Advisory).

Indicators of compromise

  • Network: Unusual outbound redirects from WAS servers to unknown or suspicious external domains; HTTP responses containing unexpected Location: headers pointing to external sites.
  • Logs: WAS access logs showing requests with URL-encoded script tags (%3Cscript%3E, javascript:, data:) or suspicious redirect parameters in query strings; error logs indicating unexpected URL parsing activity.
  • Browser/Client: Users reporting unexpected redirects to unfamiliar sites after clicking links associated with WAS-hosted applications; browser security warnings triggered by redirected destinations.

Mitigation and workarounds

IBM has released patched versions addressing this vulnerability: WebSphere Application Server 8.5.5.29 or later, WebSphere Application Server 9.0.5.27 or later, and WebSphere Application Server Liberty 26.0.0.1 or later. Patches have also been issued for numerous downstream IBM products including CICS Transaction Gateway, IBM Cloud Pak for Business Automation, IBM Business Automation Workflow, IBM Application Performance Management, IBM PowerVM Novalink, IBM Security Verify Access, and IBM Business Automation Insights. As interim mitigations, organizations should implement strict input validation, deploy Web Application Firewall (WAF) rules to detect XSS patterns, enforce Content Security Policy (CSP) headers, and monitor for suspicious URL redirects (IBM Advisory, IBM APM Advisory, IBM Verify Access Advisory).

Community reactions

Coverage of CVE-2025-12635 has been primarily technical and advisory-focused, with security news outlets such as GBHackers, CyberSecurityNews, and Cybernoz reporting on the broader IBM Security Verify Access vulnerability disclosures that include this CVE. IBM has issued multiple security bulletins across its product portfolio acknowledging the issue and providing remediation guidance. No significant independent researcher commentary or social media controversy has been observed beyond routine vulnerability tracking (GBHackers, CyberSecurityNews).

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere Application Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8400CRITICAL9.8
  • IBM JDK logoIBM JDK
  • java-1.8.0-ibm-demo
NoYesAug 05, 2026
CVE-2026-14525CRITICAL9.4
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesAug 13, 2026
CVE-2026-11536HIGH8.5
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesJul 30, 2026
CVE-2026-18499HIGH8.1
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesAug 12, 2026
CVE-2026-10571MEDIUM5.3
  • IBM WebSphere Application Server logoIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management