Ibm Websphere Application Server vulnerabilities

442 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
442
CISA KEV
1
actively exploited
Public exploits
12
Exploited in wild
2
Severity breakdown
CRITICAL49HIGH92MEDIUM261LOW40

Vulnerabilities

Page 11 of 23
CVE-2014-3070MEDIUMCVSS 5.0v8.5.0.0v8.5.0.1+14 more2014-08-22
CVE-2014-3070 [MEDIUM] CWE-264 CVE-2014-3070: The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2014-0965MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+35 more2014-08-22
CVE-2014-0965 [MEDIUM] CWE-200 CVE-2014-0965: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted SOAP response.
nvd
CVE-2014-3083MEDIUMCVSS 5.0v8.5.0.0v8.5.0.1+43 more2014-08-22
CVE-2014-3083 [MEDIUM] CWE-264 CVE-2014-3083: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x befor IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource access, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-3022MEDIUMCVSS 4.3v8.0.0.0v8.0.0.1+35 more2014-08-22
CVE-2014-3022 [MEDIUM] CWE-200 CVE-2014-3022: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition.
nvd
CVE-2014-3087MEDIUMCVSS 4.0v7.22014-08-17
CVE-2014-3087 [MEDIUM] CWE-200 CVE-2014-3087: callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Editio callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2014-0957MEDIUMCVSS 4.3v7.22014-07-18
CVE-2014-0957 [MEDIUM] CWE-79 CVE-2014-0957: Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebS Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure.
nvd
CVE-2014-0891MEDIUMCVSS 5.0v7.0v7.0.0.1+40 more2014-06-28
CVE-2014-0891 [MEDIUM] CWE-200 CVE-2014-0891: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information by leveraging incorrect request handling by the (1) Proxy or (2) ODR server.
nvd
CVE-2014-0964HIGHCVSS 7.1v6.1.0.0v6.1.0.1+56 more2014-05-16
CVE-2014-0964 [HIGH] CVE-2014-0964: IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.
nvd
CVE-2014-0859MEDIUMCVSS 5.0v8.0.0.0v8.0.0.1+40 more2014-05-01
CVE-2014-0859 [MEDIUM] CVE-2014-0859: The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0. The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, when POST retries are enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
nvd
CVE-2014-0857MEDIUMCVSS 4.0v8.5.0.0v8.5.0.1+13 more2014-05-01
CVE-2014-0857 [MEDIUM] CWE-200 CVE-2014-0857: The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x be The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.
nvd
CVE-2014-0896MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+3 more2014-05-01
CVE-2014-0896 [MEDIUM] CWE-200 CVE-2014-0896: IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information via a crafted request.
nvd
CVE-2014-0823MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+13 more2014-05-01
CVE-2014-0823 [MEDIUM] CWE-200 CVE-2014-0823: IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote att IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote attackers to read arbitrary files via a crafted URL.
nvd
CVE-2013-6323LOWCVSS 3.5v7.0v7.0.0.1+40 more2014-05-01
CVE-2013-6323 [LOW] CWE-79 CVE-2013-6323: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-6325MEDIUMCVSS 4.3v8.0.0.0v8.0.0.1+38 more2014-01-16
CVE-2013-6325 [MEDIUM] CWE-20 CVE-2013-6325: IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote attackers to cause a denial of service (resource consumption) via a crafted request to a web services endpoint.
nvd
CVE-2013-6330LOWCVSS 3.5v7.0v7.0.0.1+20 more2014-01-16
CVE-2013-6330 [LOW] CWE-200 CVE-2013-6330: IBM WebSphere Application Server 7.x before 7.0.0.31, when simpleFileServlet static file caching is IBM WebSphere Application Server 7.x before 7.0.0.31, when simpleFileServlet static file caching is enabled, allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2013-6725LOWCVSS 3.5v6.1v7.0+39 more2014-01-16
CVE-2013-6725 [LOW] CWE-79 CVE-2013-6725: Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-5417MEDIUMCVSS 4.3v7.0v7.0.0.1+37 more2013-11-18
CVE-2013-5417 [MEDIUM] CWE-79 CVE-2013-5417: Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0. Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via HTTP response data.
nvd
CVE-2013-4006MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+2 more2013-11-18
CVE-2013-4006 [MEDIUM] CWE-310 CVE-2013-4006: IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.
nvd
CVE-2013-5418LOWCVSS 3.5v7.0v7.0.0.1+37 more2013-11-18
CVE-2013-5418 [LOW] CWE-79 CVE-2013-5418: Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-5414LOWCVSS 3.5v7.0v7.0.0.1+37 more2013-11-18
CVE-2013-5414 [LOW] CWE-264 CVE-2013-5414: The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 befor The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a m
nvd