cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 17 of 24
CVE-2012-2190P4MEDIUMCVSS 5.0v6.1.0v6.1.0.0+45 more2012-08-21
CVE-2012-2190 [MEDIUM] CWE-310 CVE-2012-2190: IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1, allows remote attackers to cause a denial of service (daemon crash) via a crafted ClientHello message in the TLS Handshake Protocol.
nvd
CVE-2009-0432P4MEDIUMCVSS 5.0v6.1.0.1v6.1.0.2+8 more2009-02-10
CVE-2009-0432 [MEDIUM] CWE-16 CVE-2009-0432: The installation process for the File Transfer servlet in the System Management/Repository component The installation process for the File Transfer servlet in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19 does not enable the secure version, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2009-1900P4MEDIUMCVSS 5.0≤ 6.0.2.33v6.0.2+31 more2009-06-03
CVE-2009-1900 [MEDIUM] CWE-200 CVE-2009-1900: The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server ( The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5, when tracing is enabled, allow remote attackers to obtain sensitive information via unspecified use of the wsadmin scripting tool.
nvd
CVE-2009-0435P4MEDIUMCVSS 5.0v6.1.0v6.1.0.0+23 more2009-02-10
CVE-2009-0435 [MEDIUM] CVE-2009-0435: Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Mes Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Message Service (JMS) component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.17 on AIX 5.3 allows attackers to cause a denial of service (daemon crash) via vectors related to the aio_getioev2 and getEvent methods.
nvd
CVE-2010-0775P4MEDIUMCVSS 5.0v6.0v6.0.0.1+74 more2010-05-17
CVE-2010-0775 [MEDIUM] CWE-399 CVE-2010-0775: Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (memory consumption and daemon crash) via a crafted request, related to the nodeagent and Deployment Manager components.
nvd
CVE-2009-1898P4MEDIUMCVSS 5.0≤ 6.0.2.33v6.0.2+31 more2009-06-03
CVE-2009-1898 [MEDIUM] CWE-200 CVE-2009-1898: The secure login page in the Administrative Console component in IBM WebSphere Application Server (W The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.
nvd
CVE-2008-5411P4MEDIUMCVSS 5.0≤ 7.02008-12-10
CVE-2008-5411 [MEDIUM] CWE-310 CVE-2008-5411: IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," whic IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2008-3236P4MEDIUMCVSS 5.0v5.1.0v5.1.1+18 more2008-07-21
CVE-2008-3236 [MEDIUM] CWE-310 CVE-2008-3236: Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allows attackers to obtain sensitive information via vectors related to "previously encrypted properties" that are not encrypted.
nvd
CVE-2012-2170P4MEDIUMCVSS 4.3v7.0v7.0.0.1+14 more2012-06-20
CVE-2012-2170 [MEDIUM] CWE-264 CVE-2012-2170: The Application Snoop Servlet in IBM WebSphere Application Server 7.0 before 7.0.0.23 does not prope The Application Snoop Servlet in IBM WebSphere Application Server 7.0 before 7.0.0.23 does not properly restrict access, which allows remote attackers to obtain sensitive client and request information via a direct request.
nvd
CVE-2013-6325P4MEDIUMCVSS 4.3v8.0.0.0v8.0.0.1+38 more2014-01-16
CVE-2013-6325 [MEDIUM] CWE-20 CVE-2013-6325: IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote attackers to cause a denial of service (resource consumption) via a crafted request to a web services endpoint.
nvd
CVE-2014-0965P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+35 more2014-08-22
CVE-2014-0965 [MEDIUM] CWE-200 CVE-2014-0965: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted SOAP response.
nvd
CVE-2014-6167P4MEDIUMCVSS 4.3v7.0.0.1v7.0.0.2+46 more2014-12-18
CVE-2014-6167 [MEDIUM] CWE-79 CVE-2014-6167: Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application S Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-0542P4MEDIUMCVSS 4.3≤ 6.1.0.45v6.1.0+52 more2013-04-24
CVE-2013-0542 [MEDIUM] CWE-79 CVE-2013-0542: Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via crafted field values.
nvd
CVE-2013-0461P4MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+48 more2013-01-27
CVE-2013-0461 [MEDIUM] CWE-79 CVE-2013-0461: Cross-site scripting (XSS) vulnerability in the virtual member manager (VMM) administrative console Cross-site scripting (XSS) vulnerability in the virtual member manager (VMM) administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2016-0377P4MEDIUMCVSS 4.3v7.0.0.0v7.0.0.1+64 more2016-10-22
CVE-2016-0377 [MEDIUM] CWE-200 CVE-2016-0377: The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x befo The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2018-1902P4MEDIUMCVSS 4.3fixed in 19.0.0.3≥ 7.0.0.0, ≤ 7.0.0.45+7 more2019-03-11
CVE-2018-1902 [MEDIUM] CWE-200 CVE-2018-1902: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof conne IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof connection information which could be used to launch further attacks against the system. IBM X-Force ID: 152531.
nvd
CVE-2015-0106P4MEDIUMCVSS 4.3v7.1v7.2+5 more2015-03-24
CVE-2015-0106 [MEDIUM] CWE-79 CVE-2015-0106: Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2 Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2024-22329P4MEDIUMCVSS 4.3≥ 8.5.0.0, < 8.5.5.26≥ 9.0.0.0, < 9.0.5.20+2 more2024-04-17
CVE-2024-22329 [MEDIUM] CWE-918 CVE-2024-22329: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to conduct the SSRF attack. X-Force ID: 279951.
nvd
CVE-2011-1355P4MEDIUMCVSS 5.8v6.1v6.1.0+42 more2011-07-19
CVE-2011-1355 [MEDIUM] CWE-20 CVE-2011-1355: Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 be Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage parameter.
nvd
CVE-2001-0824P4HIGHCVSS 7.5v3.0.2v3.52001-12-06
CVE-2001-0824 [HIGH] CVE-2001-0824: Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to exec Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
nvd