Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 11 of 26
CVE-2019-4080P4MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-04-02
CVE-2019-4080 [MEDIUM] CWE-400 CVE-2019-4080: IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential d
IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter parsing. A remote attacker could exploit this to consume all available CPU resources. IBM X-Force ID: 157380.
nvd
CVE-2012-3304P4MEDIUMCVSS 6.8v6.1.0v6.1.0.0+49 more2012-09-25
CVE-2012-3304 [MEDIUM] CVE-2012-3304: The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before
The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors.
nvd
CVE-2016-2960P4LOWCVSS 3.7v7.0v7.0.0.0+64 more2016-08-08
CVE-2016-2960 [LOW] CWE-284 CVE-2016-2960: IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.
nvd
CVE-2017-1382P4HIGHCVSS 7.1≥ 7.0.0.0, ≤ 7.0.0.43≥ 8.0.0.0, ≤ 8.0.0.13+6 more2017-07-24
CVE-2017-1382 [HIGH] CWE-276 CVE-2017-1382: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permiss
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.
nvd
CVE-2009-0904P4MEDIUMCVSS 6.4v6.1v6.1.0+26 more2009-07-05
CVE-2009-0904 [MEDIUM] CWE-264 CVE-2009-0904: The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS)
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.
nvd
CVE-2017-1504P4MEDIUMCVSS 6.5v9.0.0.4v9.02017-08-03
CVE-2017-1504 [MEDIUM] CVE-2017-1504: IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after u
IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES password encryption. IBM X-Force ID: 129579.
nvd
CVE-2018-1719P4MEDIUMCVSS 5.9≥ 8.5.0.0, ≤ 8.5.5.14≥ 9.0.0.0, ≤ 9.0.0.8+2 more2018-09-14
CVE-2018-1719 [MEDIUM] CVE-2018-1719: IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certa
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This could result in a downgrade of TLS protocol. A remote attacker could exploit this vulnerability to perform man-in-the-middle attacks. IBM X-Force ID: 147292.
nvd
CVE-2026-16192P4MEDIUMCVSS 6.5≥ 17.0.0.3, < 26.0.0.92026-07-28
CVE-2026-16192 [MEDIUM] CWE-674 CVE-2026-16192: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of serv
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled.
nvd
CVE-2008-4678P4HIGHCVSS 7.8v6.0.2v6.0.2.1+14 more2008-10-22
CVE-2008-4678 [HIGH] CWE-399 CVE-2008-4678: The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (
The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."
nvd
CVE-2006-7198P4CRITICALCVSS 10.0v5.1.1.14≤ 6.0.2.112007-04-30
CVE-2006-7198 [CRITICAL] CVE-2006-7198: Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/O
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and attack vectors, related to a "Potential security exposure," aka PK26123.
nvd
CVE-2008-0389P4CRITICALCVSS 10.0≤ 5.1.1.17v5.1.1+37 more2008-01-23
CVE-2008-0389 [CRITICAL] CVE-2008-0389: Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Applicatio
Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.
nvd
CVE-2023-50315P4MEDIUMCVSS 5.9v8.5.0.0v9.0.0.0+1 more2024-08-14
CVE-2023-50315 [MEDIUM] CWE-295 CVE-2023-50315: IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to c
IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274714.
nvd
CVE-2006-2429P4CRITICALCVSS 10.0v6.0.2v6.0.2.1+3 more2006-05-17
CVE-2006-2429 [CRITICAL] CVE-2006-2429: Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers".
nvd
CVE-2007-5483P4CRITICALCVSS 10.0v5.1.1v5.1.1.1+31 more2007-10-16
CVE-2007-5483 [CRITICAL] CVE-2007-5483: Unspecified vulnerability in the Administrative Scripting Tools (such as wsadmin or ANT) in IBM WebS
Unspecified vulnerability in the Administrative Scripting Tools (such as wsadmin or ANT) in IBM WebSphere Application Server 5.x and 6.0.x has unknown impact and attack vectors.
nvd
CVE-2010-1182P4HIGHCVSS 7.5v7.0v7.0.0.1+7 more2010-03-29
CVE-2010-1182 [HIGH] CVE-2010-1182: Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Serv
Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknown impact and attack vectors.
nvd
CVE-2024-45086P4MEDIUMCVSS 5.5≥ 8.5.0.0, < 8.5.5.27≥ 9.0.0.0, < 9.0.5.22+1 more2024-11-04
CVE-2024-45086 [MEDIUM] CWE-611 CVE-2024-45086: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
nvd
CVE-2024-45072P4MEDIUMCVSS 5.5≥ 8.5.0.0, ≤ 8.5.5.26≥ 9.0.0.0, ≤ 9.0.5.21+1 more2024-10-16
CVE-2024-45072 [MEDIUM] CWE-611 CVE-2024-45072: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
nvd
CVE-2010-2324P4HIGHCVSS 7.5≤ 7.0.0.10v7.0+9 more2010-06-18
CVE-2010-2324 [HIGH] CVE-2010-2324: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows attackers to perform unspe
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows attackers to perform unspecified "link injection" actions via unknown vectors.
nvd
CVE-2026-16188P4MEDIUMCVSS 5.3v9.0v8.52026-09-14
CVE-2026-16188 [MEDIUM] CWE-117 CVE-2026-16188: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log ent
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.
nvd
CVE-2012-3306P4MEDIUMCVSS 6.8v6.1.0v6.1.0.0+49 more2012-09-25
CVE-2012-3306 [MEDIUM] CWE-255 CVE-2012-3306: IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5,
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified impact and remote attack vectors.
nvd