Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 13 of 26
CVE-2026-9338P4MEDIUMCVSS 5.3≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-09-10
CVE-2026-9338 [MEDIUM] CWE-400 CVE-2026-9338: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sendin
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to reduced availability of the affected service.
nvd
CVE-2026-11538P4MEDIUMCVSS 5.3≥ 8.5, < 8.5.5.31≥ 9.0, < 9.0.5.29+2 more2026-09-18
CVE-2026-11538 [MEDIUM] CWE-117 CVE-2026-11538: IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through cr
IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.
nvd
CVE-2014-6166P4MEDIUMCVSS 4.3v8.0.0.0v8.0.0.1+15 more2014-12-18
CVE-2014-6166 [MEDIUM] CVE-2014-6166: The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x befo
The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2011-1320P4MEDIUMCVSS 6.8v6.1.0v6.1.0.0+30 more2011-03-08
CVE-2011-1320 [MEDIUM] CWE-20 CVE-2011-1320: The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x bef
The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when the Tivoli Integrated Portal / embedded WebSphere Application Server (TIP/eWAS) framework is used, does not properly delete AuthCache entries upon a logout, which might allow remote attackers to access the server by leveraging an unatt
nvd
CVE-2017-1503P4MEDIUMCVSS 6.1v7.0v8.0+2 more2017-10-10
CVE-2017-1503 [MEDIUM] CWE-79 CVE-2017-1503: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to HTTP response splitting att
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-sit
nvd
CVE-2023-50312P4MEDIUMCVSS 6.5≥ 17.0.0.3, < 24.0.0.32024-03-01
CVE-2023-50312 [MEDIUM] CWE-327 CVE-2023-50312: IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expecte
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274711.
nvd
CVE-2012-3325P4MEDIUMCVSS 6.0v6.1v6.1.0+54 more2012-08-30
CVE-2012-3325 [MEDIUM] CWE-20 CVE-2012-3325: IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed, does not properly validate credentials, which allows remote authenticated users to obtain administrative access via unspecified vectors.
nvd
CVE-2015-1936P4MEDIUMCVSS 6.0v8.0.0.0v8.0.0.1+18 more2015-07-14
CVE-2015-1936 [MEDIUM] CWE-284 CVE-2015-1936: The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 b
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.
nvd
CVE-2020-10693P4MEDIUMCVSS 5.3≥ 17.0.0.3, ≤ 20.0.0.102020-05-06
CVE-2020-10693 [MEDIUM] CWE-20 CVE-2020-10693: A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation proc
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
nvd
CVE-2017-1788P4MEDIUMCVSS 5.3≥ 9.0.0.0, ≤ 9.0.0.7v92018-03-22
CVE-2017-1788 [MEDIUM] CVE-2017-1788: IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to c
IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 137031.
nvd
CVE-2022-22365P4MEDIUMCVSS 5.9≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2022-05-20
CVE-2022-22365 [MEDIUM] CVE-2022-22365: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxPr
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, is vulnerable to spoofing by allowing a man-in-the-middle attacker to spoof SSL server hostnames. IBM X-Force ID: 220904.
nvd
CVE-2006-5323P4CRITICALCVSS 10.0≤ 6.1.0.12006-10-17
CVE-2006-5323 [CRITICAL] CVE-2006-5323: Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact
Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360.
nvd
CVE-2019-4441P4MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+8 more2019-10-03
CVE-2019-4441 [MEDIUM] CWE-209 CVE-2019-4441: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to ob
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.
nvd
CVE-2006-3232P4CRITICALCVSS 10.0v2.0v3.0+48 more2006-06-27
CVE-2006-3232 [CRITICAL] CVE-2006-3232: Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and
Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."
nvd
CVE-2014-0964P4HIGHCVSS 7.1v6.1.0.0v6.1.0.1+56 more2014-05-16
CVE-2014-0964 [HIGH] CVE-2014-0964: IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows
IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.
nvd
CVE-2011-1309P4HIGHCVSS 7.5≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1309 [HIGH] CWE-20 CVE-2011-1309: The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly ha
The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.
nvd
CVE-2026-10571P4MEDIUMCVSS 5.3≥ 17.0.0.3, < 26.0.0.92026-08-13
CVE-2026-10571 [MEDIUM] CWE-502 CVE-2026-10571: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of serv
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled.
nvd
CVE-2016-0359P4MEDIUMCVSS 6.1v7.0v7.0.0.0+58 more2016-07-03
CVE-2016-0359 [MEDIUM] CVE-2016-0359: CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 befo
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 Full before 8.5.5.10, and 8.5 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
nvd
CVE-2026-11711P4MEDIUMCVSS 6.5v9.0v8.52026-09-18
CVE-2026-11711 [MEDIUM] CWE-502 CVE-2026-11711: IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the N
IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.
nvd
CVE-2016-0306P4MEDIUMCVSS 5.9v7.0.0.0v7.0.0.1+47 more2016-05-17
CVE-2016-0306 [MEDIUM] CWE-200 CVE-2016-0306: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
nvd