Ibm Websphere Application Server vulnerabilities
467 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40
Vulnerabilities
Page 12 of 24
CVE-2015-0175P4MEDIUMCVSS 5.5v8.5.0.0v8.5.0.1+6 more2015-04-27
CVE-2015-0175 [MEDIUM] CWE-264 CVE-2015-0175: IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implemen
IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenticated users to gain privileges via unspecified vectors.
nvd
CVE-2016-9736P4MEDIUMCVSS 5.3v8.0v8.5+2 more2017-06-08
CVE-2016-9736 [MEDIUM] CWE-200 CVE-2016-9736: IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obta
IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.
nvd
CVE-2014-0964P4HIGHCVSS 7.1v6.1.0.0v6.1.0.1+56 more2014-05-16
CVE-2014-0964 [HIGH] CVE-2014-0964: IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows
IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.
nvd
CVE-2018-1996P4MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-02-19
CVE-2018-1996 [MEDIUM] CWE-327 CVE-2018-1996: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security,
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the improper TLS configuration. A remote attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 154650.
nvd
CVE-2001-0962P4HIGHCVSS 7.5≤ 3.5.32001-09-19
CVE-2001-0962 [HIGH] CVE-2001-0962: IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which a
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
nvd
CVE-2011-1359P4MEDIUMCVSS 5.0v6.1v6.1.0+44 more2011-09-06
CVE-2011-1359 [MEDIUM] CWE-22 CVE-2011-1359: Directory traversal vulnerability in the administration console in IBM WebSphere Application Server
Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
nvd
CVE-2014-4764P4HIGHCVSS 7.1v8.5.0.0v8.5.0.1+14 more2014-08-22
CVE-2014-4764 [HIGH] CVE-2014-4764: IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Bal
IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial of service (Load Balancer crash) via unspecified vectors.
nvd
CVE-2022-34165P4MEDIUMCVSS 5.4≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+7 more2022-09-09
CVE-2022-34165 [MEDIUM] CWE-74 CVE-2022-34165: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and cross-site scripting. IBM X-Force ID
nvd
CVE-2025-12635P4MEDIUMCVSS 5.4≥ 8.5, < 8.5.5.29≥ 9.0, < 9.0.5.27+3 more2025-12-08
CVE-2025-12635 [MEDIUM] CWE-79 CVE-2025-12635: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious site.
nvd
CVE-2018-1643P4MEDIUMCVSS 6.1≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-11-15
CVE-2018-1643 [MEDIUM] CWE-79 CVE-2018-1643: The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vul
The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144588
nvd
CVE-2018-1798P4MEDIUMCVSS 6.1≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-11-12
CVE-2018-1798 [MEDIUM] CWE-79 CVE-2018-1798: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 149428.
nvd
CVE-2023-50313P4MEDIUMCVSS 6.5v8.5v9.0+1 more2024-04-02
CVE-2023-50313 [MEDIUM] CWE-327 CVE-2023-50313: IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outboun
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274812.
nvd
CVE-2026-11594P4MEDIUMCVSS 6.1≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-30
CVE-2026-11594 [MEDIUM] CWE-79 CVE-2026-11594: IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.
nvd
CVE-2016-0389P4MEDIUMCVSS 5.3v8.5.5.2v8.5.5.3+6 more2016-07-07
CVE-2016-0389 [MEDIUM] CWE-200 CVE-2016-0389: Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Libert
Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2019-4305P4MEDIUMCVSS 5.3fixed in 19.0.0.10vLiberty2019-09-30
CVE-2019-4305 [MEDIUM] CWE-565 CVE-2019-4305: IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive informati
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the improper setting of a cookie. IBM X-Force ID: 160951.
nvd
CVE-2021-29842P4MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+7 more2021-09-16
CVE-2021-29842 [MEDIUM] CWE-307 CVE-2021-29842: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allo
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.
nvd
CVE-2019-4285P4MEDIUMCVSS 5.4vLiberty2019-07-30
CVE-2019-4285 [MEDIUM] CWE-1021 CVE-2019-4285: IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the
IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a specially-crafted HTTP request to hijack the victim's click actions or launch other client-side browser attacks. IBM X-Force ID: 160513.
nvd
CVE-2006-4136P4HIGHCVSS 7.5≤ 6.1.0.0v6.0+14 more2006-08-14
CVE-2006-4136 [HIGH] CWE-200 CVE-2006-4136: Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspeci
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadIdentitySupport, and possibly others.
nvd
CVE-2022-22473P4MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2022-07-14
CVE-2022-22473 [MEDIUM] CVE-2022-22473: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sens
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force ID: 225347.
nvd
CVE-2020-4421P4MEDIUMCVSS 5.4≥ 19.0.0.5, < 20.0.0.52020-05-06
CVE-2020-4421 [MEDIUM] CWE-290 CVE-2020-4421: IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using
IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.
nvd