cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 16 of 24
CVE-2012-0193P4MEDIUMCVSS 5.0v6.0.0.0v6.0.0.2+65 more2012-01-20
CVE-2012-0193 [MEDIUM] CWE-20 CVE-2012-0193: IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.2 IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
nvd
CVE-2010-0563P4MEDIUMCVSS 5.0v7.0v7.0.0.1+4 more2010-02-08
CVE-2010-0563 [MEDIUM] CWE-200 CVE-2010-0563: The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0 The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.
nvd
CVE-2015-7417P4MEDIUMCVSS 5.4v7.0.0.0v7.0.0.1+45 more2016-01-23
CVE-2015-7417 [MEDIUM] CWE-79 CVE-2015-7417: Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8. Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.
nvd
CVE-2014-3083P4MEDIUMCVSS 5.0v8.5.0.0v8.5.0.1+43 more2014-08-22
CVE-2014-3083 [MEDIUM] CWE-264 CVE-2014-3083: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x befor IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource access, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-6164P4MEDIUMCVSS 5.0v8.0.0.0v8.0.0.1+15 more2014-12-18
CVE-2014-6164 [MEDIUM] CWE-200 CVE-2014-6164: IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attack IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL.
nvd
CVE-2017-1741P4MEDIUMCVSS 4.3v7.0v8.0+2 more2018-03-14
CVE-2017-1741 [MEDIUM] CWE-200 CVE-2017-1741: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sens IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could read files on the file system. IBM X-Force ID: 134931.
nvd
CVE-2013-0482P4MEDIUMCVSS 4.3v7.0v7.0.0.1+32 more2013-05-29
CVE-2013-0482 [MEDIUM] CVE-2013-0482: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5. IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a "Signature Wrap attack," a different vulnerability
nvd
CVE-2017-1743P4MEDIUMCVSS 4.3v7.0v8.0+2 more2018-05-04
CVE-2017-1743 [MEDIUM] CWE-200 CVE-2017-1743: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sens IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could browse the file system. IBM X-Force ID: 134933.
nvd
CVE-2015-2017P4MEDIUMCVSS 4.3v6.1v6.1.0+82 more2015-11-08
CVE-2015-2017 [MEDIUM] CVE-2015-2017: CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 bef CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
nvd
CVE-2010-0774P4MEDIUMCVSS 4.3v6.0v6.0.0.1+74 more2010-05-17
CVE-2010-0774 [MEDIUM] CWE-264 CVE-2010-0774: The (1) JAX-RPC WS-Security 1.0 and (2) JAX-WS runtime implementations in IBM WebSphere Application The (1) JAX-RPC WS-Security 1.0 and (2) JAX-WS runtime implementations in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 do not properly handle WebServices PKCS#7 and PKIPath tokens, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2009-0436P4HIGHCVSS 7.2v6.0v6.0.0.1+57 more2009-02-10
CVE-2009-0436 [HIGH] CWE-264 CVE-2009-0436: The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x befo The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS), set incorrect permissions for AF_UNIX sockets, which has unknown impact and local attack vectors.
nvd
CVE-2008-4284P4MEDIUMCVSS 5.8v5.0v5.0.0+106 more2009-02-10
CVE-2008-4284 [MEDIUM] CWE-59 CVE-2008-4284: Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server ( Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x before 6.0.2.33, and 6.1.x before 6.1.0.23 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage feature.
nvd
CVE-2006-6637P4MEDIUMCVSS 5.0v6.0.2.1v6.0.2.3+6 more2006-12-19
CVE-2006-6637 [MEDIUM] CWE-200 CVE-2006-6637: The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and other sensitive information via "specific requests."
nvd
CVE-2009-0892P4MEDIUMCVSS 5.5v6.1v6.1.0+25 more2009-03-31
CVE-2009-0892 [MEDIUM] CWE-287 CVE-2009-0892: The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 bef The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" related to a forced logout.
nvd
CVE-2014-0891P4MEDIUMCVSS 5.0v7.0v7.0.0.1+40 more2014-06-28
CVE-2014-0891 [MEDIUM] CWE-200 CVE-2014-0891: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information by leveraging incorrect request handling by the (1) Proxy or (2) ODR server.
nvd
CVE-2011-1322P4MEDIUMCVSS 5.0v6.1.0v6.1.0.0+31 more2011-03-08
CVE-2011-1322 [MEDIUM] CWE-399 CVE-2011-1322: The SOAP with Attachments API for Java (SAAJ) implementation in the Web Services component in IBM We The SOAP with Attachments API for Java (SAAJ) implementation in the Web Services component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via encrypted SOAP messages.
nvd
CVE-2010-0776P4MEDIUMCVSS 5.0v6.0v6.0.0.1+74 more2010-05-17
CVE-2010-0776 [MEDIUM] CWE-20 CVE-2010-0776: The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31 The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle chunked transfer encoding during a call to response.sendRedirect, which allows remote attackers to cause a denial of service via a GET request.
nvd
CVE-2009-2091P4MEDIUMCVSS 5.0v7.0v7.0.0.1+2 more2009-08-13
CVE-2009-2091 [MEDIUM] CWE-264 CVE-2009-2091: The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0. The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new applications, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2009-0438P4MEDIUMCVSS 5.0v7.02009-02-10
CVE-2009-0438 [MEDIUM] CVE-2009-0438: IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412.
nvd
CVE-2013-0544P4MEDIUMCVSS 4.0v6.1.0.0v6.1.0.1+51 more2013-04-24
CVE-2013-0544 [MEDIUM] CWE-22 CVE-2013-0544: Directory traversal vulnerability in the Administrative Console in IBM WebSphere Application Server Directory traversal vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux and UNIX allows remote authenticated users to modify data via unspecified vectors.
nvd