Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 16 of 26
CVE-2007-1945P4HIGHCVSS 7.5≤ 6.1.0.12007-04-11
CVE-2007-1945 [HIGH] CVE-2007-1945: Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (W
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
nvd
CVE-2021-39038P4MEDIUMCVSS 5.4≥ 9.0.0.0, < 9.0.5.12≥ 17.0.0.3, ≤ 22.0.0.2+1 more2022-02-24
CVE-2021-39038 [MEDIUM] CWE-1021 CVE-2021-39038: IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 2
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch furth
nvd
CVE-2026-11383P4MEDIUMCVSS 5.4≥ 8.5, < 8.5.5.30≥ 9.0, < 9.0.5.292026-07-30
CVE-2026-11383 [MEDIUM] CWE-79 CVE-2026-11383: IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affecte
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console.
nvd
CVE-2025-13333P4MEDIUMCVSS 4.9v8.5.0.0v9.0.0.0+2 more2026-02-17
CVE-2025-13333 [MEDIUM] CWE-358 CVE-2025-13333: IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during sys
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.
nvd
CVE-2013-3029P4MEDIUMCVSS 6.8v8.0.0.0v8.0.0.1+71 more2013-08-21
CVE-2013-3029 [MEDIUM] CWE-352 CVE-2013-3029: Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Appli
Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.
nvd
CVE-2013-0460P4MEDIUMCVSS 6.8v6.1.0.0v6.1.0.1+40 more2013-01-27
CVE-2013-0460 [MEDIUM] CWE-352 CVE-2013-0460: Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative conso
Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 and 7.0 before 7.0.0.27 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.
nvd
CVE-2009-2746P4MEDIUMCVSS 6.8v6.0.2v6.0.2.1+55 more2009-11-16
CVE-2009-2746 [MEDIUM] CWE-352 CVE-2009-2746: Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security compon
Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
nvd
CVE-2016-0283P4MEDIUMCVSS 6.1v8.5.5.0v8.5.5.1+7 more2016-03-19
CVE-2016-0283 [MEDIUM] CWE-79 CVE-2016-0283: Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM
Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2020-4575P4MEDIUMCVSS 6.1≥ 8.5.0.0, < 8.5.5.18≥ 9.0.0.0, < 9.0.5.52020-08-27
CVE-2020-4575 [MEDIUM] CWE-79 CVE-2020-4575: IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 ar
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
nvd
CVE-2023-24966P4MEDIUMCVSS 6.1≥ 8.5.0.0, < 8.5.5.24≥ 9.0.0.0, < 9.0.5.16+1 more2023-04-27
CVE-2023-24966 [MEDIUM] CWE-79 CVE-2023-24966: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 246904.
nvd
CVE-2024-27270P4MEDIUMCVSS 6.1≥ 23.0.0.3, < 24.0.0.42024-03-27
CVE-2024-27270 [MEDIUM] CWE-79 CVE-2024-27270: IBM WebSphere Application Server Liberty 23.0.0.3 through 24.0.0.3 is vulnerable to cross-site scrip
IBM WebSphere Application Server Liberty 23.0.0.3 through 24.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in a specially crafted URI. IBM X-Force ID: 284576.
nvd
CVE-2009-0891P4MEDIUMCVSS 5.5v6.0.2v6.0.2.1+56 more2009-03-25
CVE-2009-0891 [MEDIUM] CWE-287 CVE-2009-0891: The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0
The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows r
nvd
CVE-2009-3106P4MEDIUMCVSS 5.0v6.0.2v6.0.2.1+32 more2009-09-08
CVE-2009-3106 [MEDIUM] CWE-264 CVE-2009-3106: The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security constraints on the (1) doGet and (2) doTrace methods, which allows remote attackers to bypass intended access restrictions and obtain sensitive information via a crafted HTTP HEAD request to a Web Application.
nvd
CVE-2011-0316P4MEDIUMCVSS 5.0v6.1v6.1.0+32 more2011-01-12
CVE-2011-0316 [MEDIUM] CWE-264 CVE-2011-0316: The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 a
The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 does not properly restrict access to console servlets, which allows remote attackers to obtain potentially sensitive status information via a direct request.
nvd
CVE-2015-1932P4MEDIUMCVSS 5.0v7.0.0.1v7.0.0.2+52 more2015-08-22
CVE-2015-1932 [MEDIUM] CWE-200 CVE-2015-1932: IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.
nvd
CVE-2018-1777P4MEDIUMCVSS 5.4≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-10-16
CVE-2018-1777 [MEDIUM] CWE-79 CVE-2018-1777: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148800.
nvd
CVE-2009-2747P4MEDIUMCVSS 5.0v6.0v6.0.0.1+63 more2011-10-30
CVE-2009-2747 [MEDIUM] CWE-264 CVE-2009-2747: The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (W
The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call.
nvd
CVE-2011-1368P4MEDIUMCVSS 5.0v8.0.0.02011-10-29
CVE-2011-1368 [MEDIUM] CWE-200 CVE-2011-1368: The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before
The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which allows remote attackers to read unspecified files via unknown vectors.
nvd
CVE-2020-4578P4MEDIUMCVSS 5.4≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-09-10
CVE-2020-4578 [MEDIUM] CWE-79 CVE-2020-4578: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.
nvd
CVE-2019-4030P4MEDIUMCVSS 5.4≥ 8.5.0.0, ≤ 8.5.5.14≥ 9.0.0.0, ≤ 9.0.0.10+2 more2019-03-06
CVE-2019-4030 [MEDIUM] CWE-79 CVE-2019-4030: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155946.
nvd