cbcvebase.

Ibm Websphere Application Server vulnerabilities

517 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42

Vulnerabilities

Page 17 of 26
CVE-2019-4663P4MEDIUMCVSS 5.4≥ 17.0.0.3, < 19.0.0.11vLiberty2019-12-10
CVE-2019-4663 [MEDIUM] CWE-79 CVE-2019-4663: IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171245.
nvd
CVE-2022-34336P4MEDIUMCVSS 5.4v7.0v8.0+2 more2022-09-13
CVE-2022-34336 [MEDIUM] CWE-79 CVE-2022-34336: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229714.
nvd
CVE-2022-40750P4MEDIUMCVSS 5.4v8.5v9.0+1 more2022-11-11
CVE-2022-40750 [MEDIUM] CWE-79 CVE-2022-40750: IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerabil IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236588.
nvd
CVE-2007-4839P4HIGHCVSS 7.5v6.1.0.92007-09-12
CVE-2007-4839 [HIGH] CVE-2007-4839: Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1 be Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK33803.
nvd
CVE-2026-16186P4MEDIUMCVSS 5.4v9.0v8.52026-09-14
CVE-2026-16186 [MEDIUM] CWE-79 CVE-2026-16186: IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulner IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.
nvd
CVE-2014-3087P4MEDIUMCVSS 4.0v7.22014-08-17
CVE-2014-3087 [MEDIUM] CWE-200 CVE-2014-3087: callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Editio callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2014-4816P4MEDIUMCVSS 6.0v6.0v6.0.0.1+118 more2014-09-23
CVE-2014-4816 [MEDIUM] CWE-352 CVE-2014-4816: Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Appli Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2011-1311P4MEDIUMCVSS 6.0≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1311 [MEDIUM] CWE-264 CVE-2011-1311: The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 ap The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.xmi file, which might allow remote authenticated users to gain privileges in opportunistic circumstances
nvd
CVE-2010-0785P4MEDIUMCVSS 6.0v6.1v6.1.0+31 more2010-11-09
CVE-2010-0785 [MEDIUM] CWE-352 CVE-2010-0785: Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Appli Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2012-3330P4MEDIUMCVSS 5.0v7.0v7.0.0.1+22 more2012-11-14
CVE-2012-3330 [MEDIUM] CVE-2012-3330: The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8. The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterprise, allows remote attackers to cause a denial of service (daemon outage) via a crafted request.
nvd
CVE-2015-4938P4MEDIUMCVSS 5.0v7.0.0.1v7.0.0.2+52 more2015-08-22
CVE-2015-4938 [MEDIUM] CVE-2015-4938: IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5. IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vectors.
nvd
CVE-2017-1380P4MEDIUMCVSS 5.4≥ 7.0.0.0, ≤ 7.0.0.43≥ 8.0.0.0, ≤ 8.0.0.13+6 more2017-07-24
CVE-2017-1380 [MEDIUM] CWE-79 CVE-2017-1380: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127151.
nvd
CVE-2017-1121P4MEDIUMCVSS 5.4v7.0v8.0+3 more2017-02-13
CVE-2017-1121 [MEDIUM] CWE-79 CVE-2017-1121: IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulne IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997743
nvd
CVE-2019-4270P4MEDIUMCVSS 5.4≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-09-17
CVE-2019-4270 [MEDIUM] CWE-79 CVE-2019-4270: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site sc IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160203.
nvd
CVE-2010-3700P4MEDIUMCVSS 5.0v6.1v7.02010-10-29
CVE-2010-3700 [MEDIUM] CWE-264 CVE-2010-3700: VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.
nvd
CVE-2016-8934P4MEDIUMCVSS 5.4v8.5.5.0v8.5.5.1+13 more2017-02-01
CVE-2016-8934 [MEDIUM] CWE-79 CVE-2016-8934: IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows us IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2018-1957P4MEDIUMCVSS 5.5≥ 9.0.0.0, ≤ 9.0.0.9v92018-12-10
CVE-2018-1957 [MEDIUM] CWE-200 CVE-2018-1957: IBM WebSphere Application Server 9 could allow sensitive information to be available caused by misha IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629.
nvd
CVE-2023-26283P4MEDIUMCVSS 5.4v9.02023-04-02
CVE-2023-26283 [MEDIUM] CWE-79 CVE-2023-26283: IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allow IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248416.
nvd
CVE-2017-1741P4MEDIUMCVSS 4.3v7.0v8.0+2 more2018-03-14
CVE-2017-1741 [MEDIUM] CWE-200 CVE-2017-1741: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sens IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could read files on the file system. IBM X-Force ID: 134931.
nvd
CVE-2020-4365P4MEDIUMCVSS 4.3≥ 8.5.0.0, ≤ 8.5.5.17v8.52020-05-14
CVE-2020-4365 [MEDIUM] CWE-918 CVE-2020-4365: IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a spec IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase