rootpwn

medium · CVSS v3 5.3

CVE-2026-11540

IBM WebSphere Application Server 9.0 and 8.5 are vulnerable to a remote information disclosure via the FileTransfer servlet. An attacker can

Overview

IBM WebSphere Application Server 9.0 and 8.5 are vulnerable to a remote information disclosure via the FileTransfer servlet. An attacker can retrieve sensitive file system details without authentication. This flaw can aid reconnaissance or further attacks.

Description

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

Impact

Confidentiality is compromised as attackers can view file system metadata and potentially sensitive files. Integrity is not directly affected, but the information can be used to plan further exploits. Availability remains unaffected. Defenders should treat this as a potential foothold for attackers.

Remediation

Apply the latest IBM security patch for WebSphere Application Server that addresses the FileTransfer servlet vulnerability. If patching is delayed, restrict network access to the servlet by firewall rules or disable the FileTransfer feature via configuration. Monitor logs for anomalous file transfer requests.

Risk context

The CVSS v3 score of 5.3 indicates medium risk. No EPSS data is available, so prioritize based on severity and exposure. Timely patching is recommended to mitigate potential reconnaissance.

Affected products

  • IBM WebSphere 9.0
  • IBM WebSphere 8.5

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
EPSS

IBM WebSphere FileTransfer InformationDisclosure Medium CVE-2026-11540

← All CVEs