cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 15 of 24
CVE-2014-4816P4MEDIUMCVSS 6.0v6.0v6.0.0.1+118 more2014-09-23
CVE-2014-4816 [MEDIUM] CWE-352 CVE-2014-4816: Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Appli Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2010-0785P4MEDIUMCVSS 6.0v6.1v6.1.0+31 more2010-11-09
CVE-2010-0785 [MEDIUM] CWE-352 CVE-2010-0785: Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Appli Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2012-3330P4MEDIUMCVSS 5.0v7.0v7.0.0.1+22 more2012-11-14
CVE-2012-3330 [MEDIUM] CVE-2012-3330: The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8. The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterprise, allows remote attackers to cause a denial of service (daemon outage) via a crafted request.
nvd
CVE-2015-4938P4MEDIUMCVSS 5.0v7.0.0.1v7.0.0.2+52 more2015-08-22
CVE-2015-4938 [MEDIUM] CVE-2015-4938: IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5. IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vectors.
nvd
CVE-2017-1380P4MEDIUMCVSS 5.4≥ 7.0.0.0, ≤ 7.0.0.43≥ 8.0.0.0, ≤ 8.0.0.13+6 more2017-07-24
CVE-2017-1380 [MEDIUM] CWE-79 CVE-2017-1380: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127151.
nvd
CVE-2017-1121P4MEDIUMCVSS 5.4v7.0v8.0+3 more2017-02-13
CVE-2017-1121 [MEDIUM] CWE-79 CVE-2017-1121: IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulne IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997743
nvd
CVE-2019-4270P4MEDIUMCVSS 5.4≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-09-17
CVE-2019-4270 [MEDIUM] CWE-79 CVE-2019-4270: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site sc IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160203.
nvd
CVE-2016-8934P4MEDIUMCVSS 5.4v8.5.5.0v8.5.5.1+13 more2017-02-01
CVE-2016-8934 [MEDIUM] CWE-79 CVE-2016-8934: IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows us IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2010-3700P4MEDIUMCVSS 5.0v6.1v7.02010-10-29
CVE-2010-3700 [MEDIUM] CWE-264 CVE-2010-3700: VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
nvd
CVE-2018-1957P4MEDIUMCVSS 5.5≥ 9.0.0.0, ≤ 9.0.0.9v92018-12-10
CVE-2018-1957 [MEDIUM] CWE-200 CVE-2018-1957: IBM WebSphere Application Server 9 could allow sensitive information to be available caused by misha IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629.
nvd
CVE-2023-35890P4MEDIUMCVSS 5.5v8.5.5.23v9.0.5.15+2 more2023-07-07
CVE-2023-35890 [MEDIUM] CWE-327 CVE-2023-35890: IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637.
nvd
CVE-2023-26283P4MEDIUMCVSS 5.4v9.02023-04-02
CVE-2023-26283 [MEDIUM] CWE-79 CVE-2023-26283: IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allow IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248416.
nvd
CVE-2006-2435P4MEDIUMCVSS 6.4v5.0.0v5.0.1+3 more2006-05-17
CVE-2006-2435 [MEDIUM] CVE-2006-2435: Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earli Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."
nvd
CVE-2025-36099P4MEDIUMCVSS 4.9v8.5.0.0v9.0.0.0+2 more2025-09-29
CVE-2025-36099 [MEDIUM] CWE-770 CVE-2025-36099: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A privileged user could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2020-4365P4MEDIUMCVSS 4.3≥ 8.5.0.0, ≤ 8.5.5.17v8.52020-05-14
CVE-2020-4365 [MEDIUM] CWE-918 CVE-2020-4365: IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a spec IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.
nvd
CVE-2009-2749P4MEDIUMCVSS 6.4v7.0.0.72009-12-08
CVE-2009-2749 [MEDIUM] CWE-310 CVE-2009-2749: Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Applicat Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.
nvd
CVE-2002-1153P4MEDIUMCVSS 5.0v4.0.32002-10-11
CVE-2002-1153 [MEDIUM] CVE-2002-1153: IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execut IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".
nvd
CVE-2000-0497P4HIGHCVSS 7.5v3.0.22000-06-08
CVE-2000-0497 [HIGH] CWE-178 CVE-2000-0497: IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesti IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
nvd
CVE-2014-0859P4MEDIUMCVSS 5.0v8.0.0.0v8.0.0.1+40 more2014-05-01
CVE-2014-0859 [MEDIUM] CVE-2014-0859: The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0. The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, when POST retries are enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
nvd
CVE-2005-3760P4HIGHCVSS 7.8v5.02005-11-22
CVE-2005-3760 [HIGH] CWE-119 CVE-2005-3760: Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allo Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allows attackers to cause a denial of service (ABEND).
nvd
Ibm Websphere Application Server vulnerabilities | cvebase