cbcvebase.

Ibm Websphere Application Server vulnerabilities

517 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42

Vulnerabilities

Page 1 of 26
CVE-2015-7450P1CRITICALCVSS 9.8KEVPoCv7.0.0.0v8.0.0.0+3 more2016-01-02
CVE-2015-7450 [CRITICAL] CWE-502 CVE-2015-7450: Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastruct Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
nvd
CVE-2020-4450P1CRITICALCVSS 9.8ExploitedPoC≥ 8.5.0.0, < 8.5.5.18≥ 9.0.0.0, < 9.0.5.5+2 more2020-06-05
CVE-2020-4450 [CRITICAL] CWE-502 CVE-2020-4450: IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute ar IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
nvd
CVE-2019-4279P1CRITICALCVSS 9.8PoC≥ 8.5.0.0, ≤ 8.5.5.15≥ 9.0.0.0, ≤ 9.0.0.11+3 more2019-05-17
CVE-2019-4279 [CRITICAL] CWE-502 CVE-2019-4279: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.
nvd
CVE-2010-0425P2CRITICALCVSS 10.0PoC≥ 6.1, < 6.1.0.312010-03-05
CVE-2010-0425 [CRITICAL] CVE-2010-0425: modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 t modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related t
nvd
CVE-2026-14512P2CRITICALCVSS 9.8≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-07-28
CVE-2026-14512 [CRITICAL] CWE-502 CVE-2026-14512: IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
nvd
CVE-2026-16184P2CRITICALCVSS 9.8≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-07-28
CVE-2026-16184 [CRITICAL] CWE-862 CVE-2026-16184: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
nvd
CVE-2020-4448P2CRITICALCVSS 9.8≥ 8.5.0.0, < 8.5.5.18≥ 9.0.0.0, < 9.0.5.4+4 more2020-06-05
CVE-2020-4448 [CRITICAL] CWE-502 CVE-2020-4448: IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote atta IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.
nvd
CVE-2025-36038P2CRITICALCVSS 9.8≥ 8.5, < 8.5.5.28≥ 9.0, < 9.0.5.25+2 more2025-06-25
CVE-2025-36038 [CRITICAL] CWE-502 CVE-2025-36038: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
nvd
CVE-2020-4464P2HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-07-17
CVE-2020-4464 [HIGH] CWE-502 CVE-2020-4464: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.
nvd
CVE-2020-4589P2CRITICALCVSS 9.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-08-13
CVE-2020-4589 [CRITICAL] CWE-502 CVE-2020-4589: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arb IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.
nvd
CVE-2026-14974P2CRITICALCVSS 9.8≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-07-28
CVE-2026-14974 [CRITICAL] CWE-502 CVE-2026-14974: IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute a IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
nvd
CVE-2026-14976P2CRITICALCVSS 9.8≥ 17.0.0.3, < 26.0.0.92026-07-28
CVE-2026-14976 [CRITICAL] CWE-306 CVE-2026-14976: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code exec IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
nvd
CVE-2015-1920P2CRITICALCVSS 10.0v6.1v6.1.0+76 more2015-05-20
CVE-2015-1920 [CRITICAL] CWE-284 CVE-2015-1920: IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.1 IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.
nvd
CVE-2026-9319P2CRITICALCVSS 9.0≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-01
CVE-2026-9319 [CRITICAL] CWE-502 CVE-2026-9319: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due t IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
nvd
CVE-2026-8633P2CRITICALCVSS 9.8≥ 8.5.0.0, ≤ 8.5.5.29≥ 9.0.0.0, ≤ 9.0.5.272026-05-26
CVE-2026-8633 [CRITICAL] CWE-94 CVE-2026-8633: IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSpher IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.
nvd
CVE-2000-0848P3CRITICALCVSS 10.0PoCv3.0.22000-11-14
CVE-2000-0848 [CRITICAL] CVE-2000-0848: Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arb Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
nvd
CVE-2023-23477P3CRITICALCVSS 9.8v8.5v9.0+1 more2023-02-03
CVE-2023-23477 [CRITICAL] CWE-94 CVE-2023-23477: IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute ar IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513.
nvd
CVE-2018-1851P3CRITICALCVSS 9.8fixed in 18.0.0.3vLiberty2018-10-31
CVE-2018-1851 [CRITICAL] CWE-502 CVE-2018-1851: IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arb IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vulnerability to execute arbitrary code. IBM X-Force ID: 150999.
nvd
CVE-2026-9330P2HIGHCVSS 8.5≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-01
CVE-2026-9330 [HIGH] CWE-502 CVE-2026-9330: IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.
nvd
CVE-2026-14446P3CRITICALCVSS 9.8≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.28+2 more2026-07-28
CVE-2026-14446 [CRITICAL] CWE-306 CVE-2026-14446: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escal IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
nvd
1 / 26Next →
Ibm Websphere Application Server vulnerabilities | cvebase