cbcvebase.

Ibm Websphere Application Server vulnerabilities

451 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
451
CISA KEV
1
actively exploited
Public exploits
13
Exploited in wild
2
Severity breakdown
CRITICAL53HIGH95MEDIUM263LOW40

Vulnerabilities

Page 11 of 23
CVE-2014-6164MEDIUMCVSS 5.0v8.0.0.0v8.0.0.1+15 more2014-12-18
CVE-2014-6164 [MEDIUM] CWE-200 CVE-2014-6164: IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attack IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL.
nvd
CVE-2014-8890MEDIUMCVSS 5.1v8.5.0.0v8.5.0.1+5 more2014-12-18
CVE-2014-8890 [MEDIUM] CWE-264 CVE-2014-8890: IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gai IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations.
nvd
CVE-2014-3021MEDIUMCVSS 5.0v7.0v7.0.0.1+48 more2014-10-19
CVE-2014-3021 [MEDIUM] CWE-20 CVE-2014-3021: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5. IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.
nvd
CVE-2014-4816MEDIUMCVSS 6.0v6.0v6.0.0.1+118 more2014-09-23
CVE-2014-4816 [MEDIUM] CWE-352 CVE-2014-4816: Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Appli Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2014-4770LOWCVSS 3.5v6.0v6.0.0.1+118 more2014-09-23
CVE-2014-4770 [LOW] CWE-79 CVE-2014-4770: Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0 Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-4758MEDIUMCVSS 4.0v7.2v7.2.0.1+4 more2014-09-04
CVE-2014-4758 [MEDIUM] CWE-264 CVE-2014-4758: IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow re IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.
nvd
CVE-2014-3075LOWCVSS 3.5v7.2v7.2.0.1+4 more2014-09-04
CVE-2014-3075 [LOW] CWE-79 CVE-2014-3075: Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 a Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file.
nvd
CVE-2014-4764HIGHCVSS 7.1v8.5.0.0v8.5.0.1+14 more2014-08-22
CVE-2014-4764 [HIGH] CVE-2014-4764: IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Bal IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial of service (Load Balancer crash) via unspecified vectors.
nvd
CVE-2014-4767MEDIUMCVSS 6.5v8.5.0.0v8.5.0.1+4 more2014-08-22
CVE-2014-4767 [MEDIUM] CWE-94 CVE-2014-4767: IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use th IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
nvd
CVE-2014-3070MEDIUMCVSS 5.0v8.5.0.0v8.5.0.1+14 more2014-08-22
CVE-2014-3070 [MEDIUM] CWE-264 CVE-2014-3070: The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2014-0965MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+35 more2014-08-22
CVE-2014-0965 [MEDIUM] CWE-200 CVE-2014-0965: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted SOAP response.
nvd
CVE-2014-3083MEDIUMCVSS 5.0v8.5.0.0v8.5.0.1+43 more2014-08-22
CVE-2014-3083 [MEDIUM] CWE-264 CVE-2014-3083: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x befor IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource access, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-3022MEDIUMCVSS 4.3v8.0.0.0v8.0.0.1+35 more2014-08-22
CVE-2014-3022 [MEDIUM] CWE-200 CVE-2014-3022: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition.
nvd
CVE-2014-3087MEDIUMCVSS 4.0v7.22014-08-17
CVE-2014-3087 [MEDIUM] CWE-200 CVE-2014-3087: callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Editio callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2014-0957MEDIUMCVSS 4.3v7.22014-07-18
CVE-2014-0957 [MEDIUM] CWE-79 CVE-2014-0957: Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebS Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure.
nvd
CVE-2014-0891MEDIUMCVSS 5.0v7.0v7.0.0.1+40 more2014-06-28
CVE-2014-0891 [MEDIUM] CWE-200 CVE-2014-0891: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information by leveraging incorrect request handling by the (1) Proxy or (2) ODR server.
nvd
CVE-2014-0964HIGHCVSS 7.1v6.1.0.0v6.1.0.1+56 more2014-05-16
CVE-2014-0964 [HIGH] CVE-2014-0964: IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.
nvd
CVE-2014-0859MEDIUMCVSS 5.0v8.0.0.0v8.0.0.1+40 more2014-05-01
CVE-2014-0859 [MEDIUM] CVE-2014-0859: The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0. The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, when POST retries are enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
nvd
CVE-2014-0857MEDIUMCVSS 4.0v8.5.0.0v8.5.0.1+13 more2014-05-01
CVE-2014-0857 [MEDIUM] CWE-200 CVE-2014-0857: The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x be The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.
nvd
CVE-2014-0896MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+3 more2014-05-01
CVE-2014-0896 [MEDIUM] CWE-200 CVE-2014-0896: IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information via a crafted request.
nvd