Ibm Websphere Application Server vulnerabilities
467 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40
Vulnerabilities
Page 1 of 24
CVE-2015-7450P1CRITICALCVSS 9.8KEVPoCv7.0.0.0v8.0.0.0+3 more2016-01-02
CVE-2015-7450 [CRITICAL] CWE-502 CVE-2015-7450: Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastruct
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
nvd
CVE-2020-4450P1CRITICALCVSS 9.8ExploitedPoC≥ 8.5.0.0, < 8.5.5.18≥ 9.0.0.0, < 9.0.5.5+2 more2020-06-05
CVE-2020-4450 [CRITICAL] CWE-502 CVE-2020-4450: IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute ar
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
nvd
CVE-2019-4279P1CRITICALCVSS 9.8PoC≥ 8.5.0.0, ≤ 8.5.5.15≥ 9.0.0.0, ≤ 9.0.0.11+3 more2019-05-17
CVE-2019-4279 [CRITICAL] CWE-502 CVE-2019-4279: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.
nvd
CVE-2010-0425P2CRITICALCVSS 10.0PoC≥ 6.1, < 6.1.0.312010-03-05
CVE-2010-0425 [CRITICAL] CVE-2010-0425: modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 t
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related t
nvd
CVE-2020-4448P2CRITICALCVSS 9.8≥ 8.5.0.0, < 8.5.5.18≥ 9.0.0.0, < 9.0.5.4+4 more2020-06-05
CVE-2020-4448 [CRITICAL] CWE-502 CVE-2020-4448: IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote atta
IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.
nvd
CVE-2025-36038P2CRITICALCVSS 9.8≥ 8.5, < 8.5.5.28≥ 9.0, < 9.0.5.25+2 more2025-06-25
CVE-2025-36038 [CRITICAL] CWE-502 CVE-2025-36038: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
nvd
CVE-2020-4464P2HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-07-17
CVE-2020-4464 [HIGH] CWE-502 CVE-2020-4464: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.
nvd
CVE-2020-4589P2CRITICALCVSS 9.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-08-13
CVE-2020-4589 [CRITICAL] CWE-502 CVE-2020-4589: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arb
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.
nvd
CVE-2015-1920P2CRITICALCVSS 10.0v6.1v6.1.0+76 more2015-05-20
CVE-2015-1920 [CRITICAL] CWE-284 CVE-2015-1920: IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.1
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.
nvd
CVE-2026-8633P2CRITICALCVSS 9.8≥ 8.5.0.0, ≤ 8.5.5.29≥ 9.0.0.0, ≤ 9.0.5.272026-05-26
CVE-2026-8633 [CRITICAL] CWE-94 CVE-2026-8633: IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSpher
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.
nvd
CVE-2026-9319P2CRITICALCVSS 9.0≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-01
CVE-2026-9319 [CRITICAL] CWE-502 CVE-2026-9319: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due t
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
nvd
CVE-2023-23477P3CRITICALCVSS 9.8v8.5v9.0+1 more2023-02-03
CVE-2023-23477 [CRITICAL] CWE-94 CVE-2023-23477: IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute ar
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513.
nvd
CVE-2000-0848P3CRITICALCVSS 10.0PoCv3.0.22000-11-14
CVE-2000-0848 [CRITICAL] CVE-2000-0848: Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arb
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
nvd
CVE-2018-1851P3CRITICALCVSS 9.8fixed in 18.0.0.3vLiberty2018-10-31
CVE-2018-1851 [CRITICAL] CWE-502 CVE-2018-1851: IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arb
IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vulnerability to execute arbitrary code. IBM X-Force ID: 150999.
nvd
CVE-2026-9311P3CRITICALCVSS 9.0≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-01
CVE-2026-9311 [CRITICAL] CWE-94 CVE-2026-9311: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the b
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
nvd
CVE-2013-1777P3CRITICALCVSS 10.0v3.0.0.32013-07-11
CVE-2013-1777 [CRITICAL] CWE-94 CVE-2013-1777: The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Applica
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
nvd
CVE-2026-9330P2HIGHCVSS 8.5≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-01
CVE-2026-9330 [HIGH] CWE-502 CVE-2026-9330: IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.
nvd
CVE-2017-1731P3HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.43≥ 8.0.0.0, ≤ 8.0.0.14+31 more2018-01-30
CVE-2017-1731 [HIGH] CVE-2017-1731: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.
nvd
CVE-2018-1567P3CRITICALCVSS 9.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-09-07
CVE-2018-1567 [CRITICAL] CWE-502 CVE-2018-1567: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbi
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024.
nvd
CVE-2018-1904P3CRITICALCVSS 9.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-12-11
CVE-2018-1904 [CRITICAL] CWE-502 CVE-2018-1904: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbi
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.
nvd
1 / 24Next →