Ibm Websphere Application Server vulnerabilities
467 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40
Vulnerabilities
Page 13 of 24
CVE-2022-39161P4MEDIUMCVSS 5.3v7.0v8.0+3 more2023-05-03
CVE-2022-39161 [MEDIUM] CWE-295 CVE-2022-39161: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, w
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server Plug-ins for IBM WebSphere Application Server, could allow an authenticated user to conduct spoofing attacks. A man-in-the-middle attacker could exploit this vulnerability using a certificate issued by
nvd
CVE-2019-4442P4MEDIUMCVSS 4.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-09-17
CVE-2019-4442 [MEDIUM] CWE-22 CVE-2019-4442: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse di
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse directories on the file system. An attacker could send a specially-crafted URL request to view arbitrary files on the system but not content. IBM X-Force ID: 163226.
nvd
CVE-2014-0823P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+13 more2014-05-01
CVE-2014-0823 [MEDIUM] CWE-200 CVE-2014-0823: IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote att
IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote attackers to read arbitrary files via a crafted URL.
nvd
CVE-2012-4853P4MEDIUMCVSS 6.8v6.1v6.1.0+54 more2012-11-14
CVE-2012-4853 [MEDIUM] CWE-352 CVE-2012-4853: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger information disclosure.
nvd
CVE-2013-3029P4MEDIUMCVSS 6.8v8.0.0.0v8.0.0.1+71 more2013-08-21
CVE-2013-3029 [MEDIUM] CWE-352 CVE-2013-3029: Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Appli
Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.
nvd
CVE-2009-2746P4MEDIUMCVSS 6.8v6.0.2v6.0.2.1+55 more2009-11-16
CVE-2009-2746 [MEDIUM] CWE-352 CVE-2009-2746: Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security compon
Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
nvd
CVE-2018-1621P4MEDIUMCVSS 6.7v7.0.0.0v8.0.0.0+6 more2018-07-06
CVE-2018-1621 [MEDIUM] CWE-312 CVE-2018-1621: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346.
nvd
CVE-2018-1767P4MEDIUMCVSS 6.1≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-10-29
CVE-2018-1767 [MEDIUM] CWE-79 CVE-2018-1767: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scr
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148621.
nvd
CVE-2018-1794P4MEDIUMCVSS 6.1≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-10-03
CVE-2018-1794 [MEDIUM] CWE-79 CVE-2018-1794: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148949.
nvd
CVE-2018-1793P4MEDIUMCVSS 6.1v7.0v8.0+2 more2018-10-03
CVE-2018-1793 [MEDIUM] CWE-79 CVE-2018-1793: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site s
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148948.
nvd
CVE-2007-3262P4HIGHCVSS 7.8≤ 6.1.0.72007-06-19
CVE-2007-3262 [HIGH] CVE-2007-3262: Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WA
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a "TCP issue," or to MPAlarmThread and a resultant memory leak.
nvd
CVE-2020-4304P4MEDIUMCVSS 6.1≥ 17.0.0.3, ≤ 20.0.0.32020-04-02
CVE-2020-4304 [MEDIUM] CWE-79 CVE-2020-4304: IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scr
IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176670.
nvd
CVE-2020-4303P4MEDIUMCVSS 6.1≥ 17.0.0.3, ≤ 20.0.0.32020-04-02
CVE-2020-4303 [MEDIUM] CWE-79 CVE-2020-4303: IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scr
IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176668.
nvd
CVE-2022-22477P4MEDIUMCVSS 6.1v8.5v9.02022-07-14
CVE-2022-22477 [MEDIUM] CWE-79 CVE-2022-22477: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605.
nvd
CVE-2024-27270P4MEDIUMCVSS 6.1≥ 23.0.0.3, < 24.0.0.42024-03-27
CVE-2024-27270 [MEDIUM] CWE-79 CVE-2024-27270: IBM WebSphere Application Server Liberty 23.0.0.3 through 24.0.0.3 is vulnerable to cross-site scrip
IBM WebSphere Application Server Liberty 23.0.0.3 through 24.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in a specially crafted URI. IBM X-Force ID: 284576.
nvd
CVE-2009-2090P4MEDIUMCVSS 5.0v7.0v7.0.0.1+2 more2009-08-13
CVE-2009-2090 [MEDIUM] CVE-2009-2090: Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere
Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 allows remote attackers to bypass intended Java Management Extensions (JMX) Management Beans (aka MBeans) access restrictions, and cause a denial of service (daemon stop), via unknown vectors.
nvd
CVE-2014-3021P4MEDIUMCVSS 5.0v7.0v7.0.0.1+48 more2014-10-19
CVE-2014-3021 [MEDIUM] CWE-20 CVE-2014-3021: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.
nvd
CVE-2010-0786P4MEDIUMCVSS 5.0v7.0v7.0.0.1+11 more2010-11-09
CVE-2010-0786 [MEDIUM] CWE-20 CVE-2010-0786: The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 do
The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML Web Services (aka JAX-WS), which allows remote attackers to cause a denial of service (data corruption) via a crafted JAX-WS request that leads to incorrectly encoded data.
nvd
CVE-2021-39038P4MEDIUMCVSS 5.4≥ 9.0.0.0, < 9.0.5.12≥ 17.0.0.3, ≤ 22.0.0.2+1 more2022-02-24
CVE-2021-39038 [MEDIUM] CWE-1021 CVE-2021-39038: IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 2
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch furth
nvd
CVE-2007-1945P4HIGHCVSS 7.5≤ 6.1.0.12007-04-11
CVE-2007-1945 [HIGH] CVE-2007-1945: Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (W
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
nvd