Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 15 of 26
CVE-2022-22473P4MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2022-07-14
CVE-2022-22473 [MEDIUM] CVE-2022-22473: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sens
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force ID: 225347.
nvd
CVE-2006-4136P4HIGHCVSS 7.5≤ 6.1.0.0v6.0+14 more2006-08-14
CVE-2006-4136 [HIGH] CWE-200 CVE-2006-4136: Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspeci
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadIdentitySupport, and possibly others.
nvd
CVE-2014-4764P4HIGHCVSS 7.1v8.5.0.0v8.5.0.1+14 more2014-08-22
CVE-2014-4764 [HIGH] CVE-2014-4764: IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Bal
IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial of service (Load Balancer crash) via unspecified vectors.
nvd
CVE-2020-4421P4MEDIUMCVSS 5.4≥ 19.0.0.5, < 20.0.0.52020-05-06
CVE-2020-4421 [MEDIUM] CWE-290 CVE-2020-4421: IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using
IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.
nvd
CVE-2022-39161P4MEDIUMCVSS 5.3v7.0v8.0+3 more2023-05-03
CVE-2022-39161 [MEDIUM] CWE-295 CVE-2022-39161: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, w
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server Plug-ins for IBM WebSphere Application Server, could allow an authenticated user to conduct spoofing attacks. A man-in-the-middle attacker could exploit this vulnerability using a certificate issued by
nvd
CVE-2014-0823P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+13 more2014-05-01
CVE-2014-0823 [MEDIUM] CWE-200 CVE-2014-0823: IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote att
IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote attackers to read arbitrary files via a crafted URL.
nvd
CVE-2026-16189P4MEDIUMCVSS 4.8v9.0v8.52026-09-14
CVE-2026-16189 [MEDIUM] CWE-117 CVE-2026-16189: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log ent
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.
nvd
CVE-2012-4853P4MEDIUMCVSS 6.8v6.1v6.1.0+54 more2012-11-14
CVE-2012-4853 [MEDIUM] CWE-352 CVE-2012-4853: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger information disclosure.
nvd
CVE-2018-1621P4MEDIUMCVSS 6.7v7.0.0.0v8.0.0.0+6 more2018-07-06
CVE-2018-1621 [MEDIUM] CWE-312 CVE-2018-1621: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346.
nvd
CVE-2018-1767P4MEDIUMCVSS 6.1≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-10-29
CVE-2018-1767 [MEDIUM] CWE-79 CVE-2018-1767: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scr
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148621.
nvd
CVE-2018-1794P4MEDIUMCVSS 6.1≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-10-03
CVE-2018-1794 [MEDIUM] CWE-79 CVE-2018-1794: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148949.
nvd
CVE-2018-1793P4MEDIUMCVSS 6.1v7.0v8.0+2 more2018-10-03
CVE-2018-1793 [MEDIUM] CWE-79 CVE-2018-1793: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site s
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148948.
nvd
CVE-2007-3262P4HIGHCVSS 7.8≤ 6.1.0.72007-06-19
CVE-2007-3262 [HIGH] CVE-2007-3262: Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WA
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a "TCP issue," or to MPAlarmThread and a resultant memory leak.
nvd
CVE-2020-4304P4MEDIUMCVSS 6.1≥ 17.0.0.3, ≤ 20.0.0.32020-04-02
CVE-2020-4304 [MEDIUM] CWE-79 CVE-2020-4304: IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scr
IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176670.
nvd
CVE-2020-4303P4MEDIUMCVSS 6.1≥ 17.0.0.3, ≤ 20.0.0.32020-04-02
CVE-2020-4303 [MEDIUM] CWE-79 CVE-2020-4303: IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scr
IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176668.
nvd
CVE-2022-22477P4MEDIUMCVSS 6.1v8.5v9.02022-07-14
CVE-2022-22477 [MEDIUM] CWE-79 CVE-2022-22477: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605.
nvd
CVE-2026-14515P4MEDIUMCVSS 6.1≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-07-28
CVE-2026-14515 [MEDIUM] CWE-79 CVE-2026-14515: IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
nvd
CVE-2009-2090P4MEDIUMCVSS 5.0v7.0v7.0.0.1+2 more2009-08-13
CVE-2009-2090 [MEDIUM] CVE-2009-2090: Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere
Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 allows remote attackers to bypass intended Java Management Extensions (JMX) Management Beans (aka MBeans) access restrictions, and cause a denial of service (daemon stop), via unknown vectors.
nvd
CVE-2014-3021P4MEDIUMCVSS 5.0v7.0v7.0.0.1+48 more2014-10-19
CVE-2014-3021 [MEDIUM] CWE-20 CVE-2014-3021: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.
nvd
CVE-2010-0786P4MEDIUMCVSS 5.0v7.0v7.0.0.1+11 more2010-11-09
CVE-2010-0786 [MEDIUM] CWE-20 CVE-2010-0786: The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 do
The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML Web Services (aka JAX-WS), which allows remote attackers to cause a denial of service (data corruption) via a crafted JAX-WS request that leads to incorrectly encoded data.
nvd