medium · CVSS v3 5.3
CVE-2026-11540
IBM WebSphere Application Server 9.0 and 8.5 are vulnerable to a remote information disclosure via the FileTransfer servlet. An attacker can
Overview
IBM WebSphere Application Server 9.0 and 8.5 are vulnerable to a remote information disclosure via the FileTransfer servlet. An attacker can retrieve sensitive file system details without authentication. This flaw can aid reconnaissance or further attacks.
Description
IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
Impact
Confidentiality is compromised as attackers can view file system metadata and potentially sensitive files. Integrity is not directly affected, but the information can be used to plan further exploits. Availability remains unaffected. Defenders should treat this as a potential foothold for attackers.
Remediation
Apply the latest IBM security patch for WebSphere Application Server that addresses the FileTransfer servlet vulnerability. If patching is delayed, restrict network access to the servlet by firewall rules or disable the FileTransfer feature via configuration. Monitor logs for anomalous file transfer requests.
Risk context
The CVSS v3 score of 5.3 indicates medium risk. No EPSS data is available, so prioritize based on severity and exposure. Timely patching is recommended to mitigate potential reconnaissance.
Affected products
- IBM WebSphere 9.0
- IBM WebSphere 8.5
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- —