Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 (availability September 2026) or later fix pack. For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 (availability September 2026) or later fix pack.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7286610 |
|
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies. | |
| Title | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities | |
| First Time appeared |
Ibm
Ibm websphere Application Server |
|
| Weaknesses | CWE-117 | |
| CPEs | cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:* cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm websphere Application Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-18T19:46:49.750Z
Reserved: 2026-06-08T02:43:30.313Z
Link: CVE-2026-11538
Updated: 2026-09-18T19:46:45.477Z
Status : Awaiting Analysis
Published: 2026-09-18T19:16:40.957
Modified: 2026-09-18T20:17:00.220
Link: CVE-2026-11538
No data.
OpenCVE Enrichment
No data.
