Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 10 of 26
CVE-2013-0543P4MEDIUMCVSS 6.8v6.1.0.0v6.1.0.1+51 more2013-04-24
CVE-2013-0543 [MEDIUM] CWE-863 CVE-2013-0543: IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6,
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2018-1838P4MEDIUMCVSS 6.5v8.5.0.0v9.0.0.0+2 more2018-10-12
CVE-2018-1838 [MEDIUM] CWE-200 CVE-2018-1838: IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain se
IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords. IBM X-Force ID: 150811.
nvd
CVE-2022-22310P4MEDIUMCVSS 6.5≥ 21.0.0.10, ≤ 21.0.0.122022-01-19
CVE-2022-22310 [MEDIUM] CVE-2022-22310: IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expec
IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 217224.
nvd
CVE-2015-0110P4MEDIUMCVSS 6.5v7.2.0.0v7.2.0.1+4 more2017-09-15
CVE-2015-0110 [MEDIUM] CWE-284 CVE-2015-0110: IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka W
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.
nvd
CVE-2022-22393P4MEDIUMCVSS 6.5≥ 17.0.0.3, ≤ 22.0.0.52022-05-13
CVE-2022-22393 [MEDIUM] CVE-2022-22393: IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 featur
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could allow an authenticated user to issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server. IBM X-Force ID: 222078.
nvd
CVE-2026-16187P3MEDIUMCVSS 6.5v9.0v8.52026-09-14
CVE-2026-16187 [MEDIUM] CWE-862 CVE-2026-16187: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.
nvd
CVE-2019-4268P4MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-09-17
CVE-2019-4268 [MEDIUM] CWE-22 CVE-2019-4268: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse di
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 160201.
nvd
CVE-2006-6636P4CRITICALCVSS 10.0v5.1.1v5.1.1.1+18 more2006-12-19
CVE-2006-6636 [CRITICAL] CVE-2006-6636: Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5
Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.
nvd
CVE-2006-6135P4CRITICALCVSS 10.0v6.1.02006-11-28
CVE-2006-6135 [CRITICAL] CVE-2006-6135: Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.
Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, related to (1) a "Potential security vulnerability" (PK29725) and (2) "Potential security exposure" (PK30831).
nvd
CVE-2008-3235P4CRITICALCVSS 10.0v5.1.0v5.1.1+18 more2008-07-21
CVE-2008-3235 [CRITICAL] CWE-255 CVE-2008-3235: Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM We
Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 has unknown impact and attack vectors.
nvd
CVE-2015-1927P4MEDIUMCVSS 6.8v7.0v7.0.0.1+52 more2015-07-14
CVE-2015-1927 [MEDIUM] CWE-284 CVE-2015-1927: The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 bef
The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors.
nvd
CVE-2019-4477P4MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-09-17
CVE-2019-4477 [MEDIUM] CWE-269 CVE-2019-4477: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive information, caused by improper handling of command line options. IBM X-Force ID: 163997.
nvd
CVE-2022-22475P4MEDIUMCVSS 6.5≥ 17.0.0.3, ≤ 22.0.0.52022-05-17
CVE-2022-22475 [MEDIUM] CVE-2022-22475: IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable t
IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM X-Force ID: 225603.
nvd
CVE-2019-4304P4MEDIUMCVSS 6.3fixed in 19.0.0.10vLiberty2019-09-30
CVE-2019-4304 [MEDIUM] CWE-384 CVE-2019-4304: IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrict
IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950.
nvd
CVE-2005-1872P4HIGHCVSS 7.5v5.02005-06-03
CVE-2005-1872 [HIGH] CVE-2005-1872: Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the glob
Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.
nvd
CVE-2008-5412P4CRITICALCVSS 10.0≤ 7.02008-12-10
CVE-2008-5412 [CRITICAL] CVE-2008-5412: Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs. NOTE: this is probably a duplicate of CVE-2009-0438.
nvd
CVE-2008-0741P4CRITICALCVSS 10.0≤ 6.0.2.242008-02-13
CVE-2008-0741 [CRITICAL] CWE-264 CVE-2008-0741: Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server
Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has unknown impact and attack vectors.
nvd
CVE-2006-2436P4HIGHCVSS 7.5v5.0.0v5.0.1+1 more2006-05-17
CVE-2006-2436 [HIGH] CVE-2006-2436: WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords i
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.
nvd
CVE-2007-1608P4HIGHCVSS 7.5≤ 6.0.2.152007-03-22
CVE-2007-1608 [HIGH] CVE-2007-1608: CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.
nvd
CVE-2008-4111P4CRITICALCVSS 9.3v6.1v6.1.0+19 more2008-09-16
CVE-2008-4111 [CRITICAL] CVE-2008-4111: Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS)
Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when the FileServing feature is enabled, has unknown impact and attack vectors.
nvd