cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 14 of 24
CVE-2007-4839P4HIGHCVSS 7.5v6.1.0.92007-09-12
CVE-2007-4839 [HIGH] CVE-2007-4839: Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1 be Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK33803.
nvd
CVE-2025-13333P4MEDIUMCVSS 4.9v8.5.0.0v9.0.0.0+2 more2026-02-17
CVE-2025-13333 [MEDIUM] CWE-358 CVE-2025-13333: IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during sys IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.
nvd
CVE-2013-0460P4MEDIUMCVSS 6.8v6.1.0.0v6.1.0.1+40 more2013-01-27
CVE-2013-0460 [MEDIUM] CWE-352 CVE-2013-0460: Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative conso Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 and 7.0 before 7.0.0.27 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.
nvd
CVE-2016-0283P4MEDIUMCVSS 6.1v8.5.5.0v8.5.5.1+7 more2016-03-19
CVE-2016-0283 [MEDIUM] CWE-79 CVE-2016-0283: Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2020-4575P4MEDIUMCVSS 6.1≥ 8.5.0.0, < 8.5.5.18≥ 9.0.0.0, < 9.0.5.52020-08-27
CVE-2020-4575 [MEDIUM] CWE-79 CVE-2020-4575: IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 ar IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
nvd
CVE-2011-1311P4MEDIUMCVSS 6.0≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1311 [MEDIUM] CWE-264 CVE-2011-1311: The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 ap The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.xmi file, which might allow remote authenticated users to gain privileges in opportunistic circumstances
nvd
CVE-2023-24966P4MEDIUMCVSS 6.1≥ 8.5.0.0, < 8.5.5.24≥ 9.0.0.0, < 9.0.5.16+1 more2023-04-27
CVE-2023-24966 [MEDIUM] CWE-79 CVE-2023-24966: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 246904.
nvd
CVE-2009-0891P4MEDIUMCVSS 5.5v6.0.2v6.0.2.1+56 more2009-03-25
CVE-2009-0891 [MEDIUM] CWE-287 CVE-2009-0891: The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0 The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows r
nvd
CVE-2009-3106P4MEDIUMCVSS 5.0v6.0.2v6.0.2.1+32 more2009-09-08
CVE-2009-3106 [MEDIUM] CWE-264 CVE-2009-3106: The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6. The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security constraints on the (1) doGet and (2) doTrace methods, which allows remote attackers to bypass intended access restrictions and obtain sensitive information via a crafted HTTP HEAD request to a Web Application.
nvd
CVE-2011-0316P4MEDIUMCVSS 5.0v6.1v6.1.0+32 more2011-01-12
CVE-2011-0316 [MEDIUM] CWE-264 CVE-2011-0316: The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 a The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 does not properly restrict access to console servlets, which allows remote attackers to obtain potentially sensitive status information via a direct request.
nvd
CVE-2015-1932P4MEDIUMCVSS 5.0v7.0.0.1v7.0.0.2+52 more2015-08-22
CVE-2015-1932 [MEDIUM] CWE-200 CVE-2015-1932: IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5. IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.
nvd
CVE-2018-1777P4MEDIUMCVSS 5.4≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-10-16
CVE-2018-1777 [MEDIUM] CWE-79 CVE-2018-1777: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148800.
nvd
CVE-2009-2747P4MEDIUMCVSS 5.0v6.0v6.0.0.1+63 more2011-10-30
CVE-2009-2747 [MEDIUM] CWE-264 CVE-2009-2747: The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (W The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call.
nvd
CVE-2011-1368P4MEDIUMCVSS 5.0v8.0.0.02011-10-29
CVE-2011-1368 [MEDIUM] CWE-200 CVE-2011-1368: The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which allows remote attackers to read unspecified files via unknown vectors.
nvd
CVE-2020-4578P4MEDIUMCVSS 5.4≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-09-10
CVE-2020-4578 [MEDIUM] CWE-79 CVE-2020-4578: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.
nvd
CVE-2019-4030P4MEDIUMCVSS 5.4≥ 8.5.0.0, ≤ 8.5.5.14≥ 9.0.0.0, ≤ 9.0.0.10+2 more2019-03-06
CVE-2019-4030 [MEDIUM] CWE-79 CVE-2019-4030: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155946.
nvd
CVE-2019-4663P4MEDIUMCVSS 5.4≥ 17.0.0.3, < 19.0.0.11vLiberty2019-12-10
CVE-2019-4663 [MEDIUM] CWE-79 CVE-2019-4663: IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171245.
nvd
CVE-2022-34336P4MEDIUMCVSS 5.4v7.0v8.0+2 more2022-09-13
CVE-2022-34336 [MEDIUM] CWE-79 CVE-2022-34336: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229714.
nvd
CVE-2022-40750P4MEDIUMCVSS 5.4v8.5v9.0+1 more2022-11-11
CVE-2022-40750 [MEDIUM] CWE-79 CVE-2022-40750: IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerabil IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236588.
nvd
CVE-2014-3087P4MEDIUMCVSS 4.0v7.22014-08-17
CVE-2014-3087 [MEDIUM] CWE-200 CVE-2014-3087: callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Editio callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase