Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 14 of 26
CVE-2026-11594P4MEDIUMCVSS 6.1≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-30
CVE-2026-11594 [MEDIUM] CWE-79 CVE-2026-11594: IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.
nvd
CVE-2016-9736P4MEDIUMCVSS 5.3v8.0v8.5+2 more2017-06-08
CVE-2016-9736 [MEDIUM] CWE-200 CVE-2016-9736: IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obta
IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.
nvd
CVE-2006-2433P4CRITICALCVSS 10.0v6.0.2v6.0.2.1+3 more2006-05-17
CVE-2006-2433 [CRITICAL] CVE-2006-2433: Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".
nvd
CVE-2018-1996P4MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-02-19
CVE-2018-1996 [MEDIUM] CWE-327 CVE-2018-1996: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security,
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the improper TLS configuration. A remote attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 154650.
nvd
CVE-2001-0962P4HIGHCVSS 7.5≤ 3.5.32001-09-19
CVE-2001-0962 [HIGH] CVE-2001-0962: IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which a
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
nvd
CVE-2011-1359P4MEDIUMCVSS 5.0v6.1v6.1.0+44 more2011-09-06
CVE-2011-1359 [MEDIUM] CWE-22 CVE-2011-1359: Directory traversal vulnerability in the administration console in IBM WebSphere Application Server
Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
nvd
CVE-2022-34165P4MEDIUMCVSS 5.4≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+7 more2022-09-09
CVE-2022-34165 [MEDIUM] CWE-74 CVE-2022-34165: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and cross-site scripting. IBM X-Force ID
nvd
CVE-2025-12635P4MEDIUMCVSS 5.4≥ 8.5, < 8.5.5.29≥ 9.0, < 9.0.5.27+3 more2025-12-08
CVE-2025-12635 [MEDIUM] CWE-79 CVE-2025-12635: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious site.
nvd
CVE-2026-11540P4MEDIUMCVSS 5.3v9.0v8.52026-09-18
CVE-2026-11540 [MEDIUM] CWE-863 CVE-2026-11540: IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive infor
IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
nvd
CVE-2019-4442P4MEDIUMCVSS 4.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-09-17
CVE-2019-4442 [MEDIUM] CWE-22 CVE-2019-4442: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse di
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse directories on the file system. An attacker could send a specially-crafted URL request to view arbitrary files on the system but not content. IBM X-Force ID: 163226.
nvd
CVE-2009-0906P4MEDIUMCVSS 6.5v1.0v1.0.0.22009-08-13
CVE-2009-0906 [MEDIUM] CWE-287 CVE-2009-0906: The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA
The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.
nvd
CVE-2011-1321P4MEDIUMCVSS 6.5v6.1.0v6.1.0.0+31 more2011-03-08
CVE-2011-1321 [MEDIUM] CWE-264 CVE-2011-1321: The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WA
The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 does not purge a user from the PlatformCredential cache, which might allow remote authenticated users to gain privileges by leveraging a group membership specified in an old RACF Object (aka RACO).
nvd
CVE-2018-1643P4MEDIUMCVSS 6.1≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-11-15
CVE-2018-1643 [MEDIUM] CWE-79 CVE-2018-1643: The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vul
The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144588
nvd
CVE-2018-1798P4MEDIUMCVSS 6.1≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-11-12
CVE-2018-1798 [MEDIUM] CWE-79 CVE-2018-1798: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 149428.
nvd
CVE-2023-50313P4MEDIUMCVSS 6.5v8.5v9.0+1 more2024-04-02
CVE-2023-50313 [MEDIUM] CWE-327 CVE-2023-50313: IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outboun
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274812.
nvd
CVE-2015-0175P4MEDIUMCVSS 5.5v8.5.0.0v8.5.0.1+6 more2015-04-27
CVE-2015-0175 [MEDIUM] CWE-264 CVE-2015-0175: IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implemen
IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenticated users to gain privileges via unspecified vectors.
nvd
CVE-2016-0389P4MEDIUMCVSS 5.3v8.5.5.2v8.5.5.3+6 more2016-07-07
CVE-2016-0389 [MEDIUM] CWE-200 CVE-2016-0389: Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Libert
Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2019-4305P4MEDIUMCVSS 5.3fixed in 19.0.0.10vLiberty2019-09-30
CVE-2019-4305 [MEDIUM] CWE-565 CVE-2019-4305: IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive informati
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the improper setting of a cookie. IBM X-Force ID: 160951.
nvd
CVE-2021-29842P4MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+7 more2021-09-16
CVE-2021-29842 [MEDIUM] CWE-307 CVE-2021-29842: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allo
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.
nvd
CVE-2019-4285P4MEDIUMCVSS 5.4vLiberty2019-07-30
CVE-2019-4285 [MEDIUM] CWE-1021 CVE-2019-4285: IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the
IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a specially-crafted HTTP request to hijack the victim's click actions or launch other client-side browser attacks. IBM X-Force ID: 160513.
nvd