Ibm Websphere Application Server vulnerabilities
467 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40
Vulnerabilities
Page 10 of 24
CVE-2024-45086P4MEDIUMCVSS 5.5≥ 8.5.0.0, < 8.5.5.27≥ 9.0.0.0, < 9.0.5.22+1 more2024-11-04
CVE-2024-45086 [MEDIUM] CWE-611 CVE-2024-45086: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
nvd
CVE-2024-45072P4MEDIUMCVSS 5.5≥ 8.5.0.0, ≤ 8.5.5.26≥ 9.0.0.0, ≤ 9.0.5.21+1 more2024-10-16
CVE-2024-45072 [MEDIUM] CWE-611 CVE-2024-45072: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
nvd
CVE-2010-2324P4HIGHCVSS 7.5≤ 7.0.0.10v7.0+9 more2010-06-18
CVE-2010-2324 [HIGH] CVE-2010-2324: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows attackers to perform unspe
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows attackers to perform unspecified "link injection" actions via unknown vectors.
nvd
CVE-2011-1683P4MEDIUMCVSS 6.8v6.0v6.0.0.1+95 more2011-04-13
CVE-2011-1683 [MEDIUM] CWE-264 CVE-2011-1683: IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x befo
IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registry or Federated Repository with RACF adapter is used, allows remote attackers to obtain unspecified application access via unknown vectors.
nvd
CVE-2012-3306P4MEDIUMCVSS 6.8v6.1.0v6.1.0.0+49 more2012-09-25
CVE-2012-3306 [MEDIUM] CWE-255 CVE-2012-3306: IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5,
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified impact and remote attack vectors.
nvd
CVE-2008-4679P4MEDIUMCVSS 6.8v6.0.1.1v6.0.1.2+24 more2008-10-22
CVE-2008-4679 [MEDIUM] CWE-287 CVE-2008-4679: The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checkin
nvd
CVE-2013-4053P4MEDIUMCVSS 6.8v8.5.0.0v8.5.0.1+66 more2013-09-20
CVE-2013-4053 [MEDIUM] CWE-20 CVE-2013-4053: The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 be
The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1, and WAS Feature Pack for Web Services 6.1 before 6.1.0.47, when a trust store is configured for XML Digital Signatures, does not properly verify X.509 certificates, which allows remote attackers
nvd
CVE-2012-2162P4MEDIUMCVSS 6.8≤ 8.0.0.0v5.0+133 more2012-05-01
CVE-2012-2162 [MEDIUM] CWE-310 CVE-2012-2162: The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HT
The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.
nvd
CVE-2020-4590P4MEDIUMCVSS 6.5≥ 17.0.0.3, ≤ 20.0.0.92020-09-21
CVE-2020-4590 [MEDIUM] CVE-2020-4590: IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnec
IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.
nvd
CVE-2017-1501P4MEDIUMCVSS 5.9v8.0.0.0v8.0.0.1+22 more2017-08-18
CVE-2017-1501 [MEDIUM] CWE-200 CVE-2017-1501: IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web services security bindings settings. IBM X-Force ID: 129576.
nvd
CVE-2022-35282P4MEDIUMCVSS 6.5≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2022-09-28
CVE-2022-35282 [MEDIUM] CWE-918 CVE-2022-35282: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker with local network access could exploit this vulnerability to obtain sensitive data.
nvd
CVE-2018-1695P4MEDIUMCVSS 5.6v7.0.0.0v8.0.0.0+4 more2018-09-06
CVE-2018-1695 [MEDIUM] CWE-290 CVE-2018-1695: IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a re
IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769.
nvd
CVE-2018-1797P4MEDIUMCVSS 5.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-11-16
CVE-2018-1797 [MEDIUM] CWE-22 CVE-2018-1797: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing "dot dot slash" sequences (../), an attacker could exploit this vulnerability to write to arbitrary files on the s
nvd
CVE-2019-4505P4MEDIUMCVSS 5.3≥ 8.5.0.0, ≤ 8.5.5.16≥ 9.0.0.0, ≤ 9.0.5.0+4 more2019-09-20
CVE-2019-4505 [MEDIUM] CVE-2019-4505: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote atta
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL. This can lead the attacker to view any file in a certain directory. IBM X-Force ID: 164364.
nvd
CVE-2006-2432P4HIGHCVSS 7.5v5.0.0v5.0.1+3 more2006-05-17
CVE-2006-2432 [HIGH] CVE-2006-2432: IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cum
IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.
nvd
CVE-2022-38712P4MEDIUMCVSS 5.9≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+2 more2022-11-03
CVE-2022-38712 [MEDIUM] CWE-290 CVE-2022-38712: "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middl
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762."
nvd
CVE-2014-8890P4MEDIUMCVSS 5.1v8.5.0.0v8.5.0.1+5 more2014-12-18
CVE-2014-8890 [MEDIUM] CWE-264 CVE-2014-8890: IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gai
IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations.
nvd
CVE-2014-3070P4MEDIUMCVSS 5.0v8.5.0.0v8.5.0.1+14 more2014-08-22
CVE-2014-3070 [MEDIUM] CWE-264 CVE-2014-3070: The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application
The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2007-3960P4CRITICALCVSS 9.3≤ 6.0.2.192007-07-24
CVE-2007-3960 [CRITICAL] CVE-2007-3960: Multiple unspecified vulnerabilities in IBM WebSphere Application Server (WAS) before Fix Pack 21 (6
Multiple unspecified vulnerabilities in IBM WebSphere Application Server (WAS) before Fix Pack 21 (6.0.2.21) have unknown impact and attack vectors, aka (1) PK33799, or (2) a "Potential security exposure" in the Samples component (PK40213).
nvd
CVE-2019-4732P4MEDIUMCVSS 6.5v7.0v8.0+2 more2020-02-03
CVE-2019-4732 [MEDIUM] CWE-426 CVE-2019-4732: IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.
IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an att
nvd