cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 11 of 24
CVE-2009-2744P4HIGHCVSS 7.8v6.1v6.1.0+27 more2009-09-21
CVE-2009-2744 [HIGH] CVE-2009-2744: Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remot Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unknown vectors, related to "an error in fixpacks 6.1.0.23 and 6.1.0.25."
nvd
CVE-2022-22365P4MEDIUMCVSS 5.9≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2022-05-20
CVE-2022-22365 [MEDIUM] CVE-2022-22365: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxPr IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, is vulnerable to spoofing by allowing a man-in-the-middle attacker to spoof SSL server hostnames. IBM X-Force ID: 220904.
nvd
CVE-2006-5323P4CRITICALCVSS 10.0≤ 6.1.0.12006-10-17
CVE-2006-5323 [CRITICAL] CVE-2006-5323: Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360.
nvd
CVE-2007-3264P4CRITICALCVSS 10.0≤ 6.1.0.72007-06-19
CVE-2007-3264 [CRITICAL] CVE-2007-3264: Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0. Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors.
nvd
CVE-2006-3232P4CRITICALCVSS 10.0v2.0v3.0+48 more2006-06-27
CVE-2006-3232 [CRITICAL] CVE-2006-3232: Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."
nvd
CVE-2011-1309P4HIGHCVSS 7.5≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1309 [HIGH] CWE-20 CVE-2011-1309: The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly ha The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.
nvd
CVE-2014-6166P4MEDIUMCVSS 4.3v8.0.0.0v8.0.0.1+15 more2014-12-18
CVE-2014-6166 [MEDIUM] CVE-2014-6166: The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x befo The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2011-1320P4MEDIUMCVSS 6.8v6.1.0v6.1.0.0+30 more2011-03-08
CVE-2011-1320 [MEDIUM] CWE-20 CVE-2011-1320: The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x bef The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when the Tivoli Integrated Portal / embedded WebSphere Application Server (TIP/eWAS) framework is used, does not properly delete AuthCache entries upon a logout, which might allow remote attackers to access the server by leveraging an unatt
nvd
CVE-2017-1503P4MEDIUMCVSS 6.1v7.0v8.0+2 more2017-10-10
CVE-2017-1503 [MEDIUM] CWE-79 CVE-2017-1503: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to HTTP response splitting att IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-sit
nvd
CVE-2023-50312P4MEDIUMCVSS 6.5≥ 17.0.0.3, < 24.0.0.32024-03-01
CVE-2023-50312 [MEDIUM] CWE-327 CVE-2023-50312: IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expecte IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274711.
nvd
CVE-2012-3325P4MEDIUMCVSS 6.0v6.1v6.1.0+54 more2012-08-30
CVE-2012-3325 [MEDIUM] CWE-20 CVE-2012-3325: IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8. IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed, does not properly validate credentials, which allows remote authenticated users to obtain administrative access via unspecified vectors.
nvd
CVE-2015-1936P4MEDIUMCVSS 6.0v8.0.0.0v8.0.0.1+18 more2015-07-14
CVE-2015-1936 [MEDIUM] CWE-284 CVE-2015-1936: The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 b The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.
nvd
CVE-2017-1788P4MEDIUMCVSS 5.3≥ 9.0.0.0, ≤ 9.0.0.7v92018-03-22
CVE-2017-1788 [MEDIUM] CVE-2017-1788: IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to c IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 137031.
nvd
CVE-2020-10693P4MEDIUMCVSS 5.3≥ 17.0.0.3, ≤ 20.0.0.102020-05-06
CVE-2020-10693 [MEDIUM] CWE-20 CVE-2020-10693: A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation proc A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
nvd
CVE-2006-2433P4CRITICALCVSS 10.0v6.0.2v6.0.2.1+3 more2006-05-17
CVE-2006-2433 [CRITICAL] CVE-2006-2433: Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".
nvd
CVE-2019-4441P4MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+8 more2019-10-03
CVE-2019-4441 [MEDIUM] CWE-209 CVE-2019-4441: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to ob IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.
nvd
CVE-2009-0906P4MEDIUMCVSS 6.5v1.0v1.0.0.22009-08-13
CVE-2009-0906 [MEDIUM] CWE-287 CVE-2009-0906: The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.
nvd
CVE-2011-1321P4MEDIUMCVSS 6.5v6.1.0v6.1.0.0+31 more2011-03-08
CVE-2011-1321 [MEDIUM] CWE-264 CVE-2011-1321: The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WA The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 does not purge a user from the PlatformCredential cache, which might allow remote authenticated users to gain privileges by leveraging a group membership specified in an old RACF Object (aka RACO).
nvd
CVE-2016-0359P4MEDIUMCVSS 6.1v7.0v7.0.0.0+58 more2016-07-03
CVE-2016-0359 [MEDIUM] CVE-2016-0359: CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 befo CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 Full before 8.5.5.10, and 8.5 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
nvd
CVE-2016-0306P4MEDIUMCVSS 5.9v7.0.0.0v7.0.0.1+47 more2016-05-17
CVE-2016-0306 [MEDIUM] CWE-200 CVE-2016-0306: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5. IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase