cbcvebase.

Ibm Websphere Application Server vulnerabilities

517 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42

Vulnerabilities

Page 18 of 26
CVE-2009-2749P4MEDIUMCVSS 6.4v7.0.0.72009-12-08
CVE-2009-2749 [MEDIUM] CWE-310 CVE-2009-2749: Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Applicat Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.
nvd
CVE-2002-1153P4MEDIUMCVSS 5.0v4.0.32002-10-11
CVE-2002-1153 [MEDIUM] CVE-2002-1153: IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execut IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".
nvd
CVE-2000-0497P4HIGHCVSS 7.5v3.0.22000-06-08
CVE-2000-0497 [HIGH] CWE-178 CVE-2000-0497: IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesti IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
nvd
CVE-2014-0859P4MEDIUMCVSS 5.0v8.0.0.0v8.0.0.1+40 more2014-05-01
CVE-2014-0859 [MEDIUM] CVE-2014-0859: The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0. The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, when POST retries are enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
nvd
CVE-2005-3760P4HIGHCVSS 7.8v5.02005-11-22
CVE-2005-3760 [HIGH] CWE-119 CVE-2005-3760: Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allo Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allows attackers to cause a denial of service (ABEND).
nvd
CVE-2012-0193P4MEDIUMCVSS 5.0v6.0.0.0v6.0.0.2+65 more2012-01-20
CVE-2012-0193 [MEDIUM] CWE-20 CVE-2012-0193: IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.2 IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
nvd
CVE-2010-0563P4MEDIUMCVSS 5.0v7.0v7.0.0.1+4 more2010-02-08
CVE-2010-0563 [MEDIUM] CWE-200 CVE-2010-0563: The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0 The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.
nvd
CVE-2015-7417P4MEDIUMCVSS 5.4v7.0.0.0v7.0.0.1+45 more2016-01-23
CVE-2015-7417 [MEDIUM] CWE-79 CVE-2015-7417: Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8. Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.
nvd
CVE-2014-3083P4MEDIUMCVSS 5.0v8.5.0.0v8.5.0.1+43 more2014-08-22
CVE-2014-3083 [MEDIUM] CWE-264 CVE-2014-3083: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x befor IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource access, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-6164P4MEDIUMCVSS 5.0v8.0.0.0v8.0.0.1+15 more2014-12-18
CVE-2014-6164 [MEDIUM] CWE-200 CVE-2014-6164: IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attack IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL.
nvd
CVE-2023-35890P4MEDIUMCVSS 5.5v8.5.5.23v9.0.5.15+2 more2023-07-07
CVE-2023-35890 [MEDIUM] CWE-327 CVE-2023-35890: IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637.
nvd
CVE-2013-0482P4MEDIUMCVSS 4.3v7.0v7.0.0.1+32 more2013-05-29
CVE-2013-0482 [MEDIUM] CVE-2013-0482: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5. IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a "Signature Wrap attack," a different vulnerability
nvd
CVE-2017-1743P4MEDIUMCVSS 4.3v7.0v8.0+2 more2018-05-04
CVE-2017-1743 [MEDIUM] CWE-200 CVE-2017-1743: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sens IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could browse the file system. IBM X-Force ID: 134933.
nvd
CVE-2015-2017P4MEDIUMCVSS 4.3v6.1v6.1.0+82 more2015-11-08
CVE-2015-2017 [MEDIUM] CVE-2015-2017: CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 bef CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
nvd
CVE-2025-36099P4MEDIUMCVSS 4.9v8.5.0.0v9.0.0.0+2 more2025-09-29
CVE-2025-36099 [MEDIUM] CWE-770 CVE-2025-36099: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A privileged user could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2006-2435P4MEDIUMCVSS 6.4v5.0.0v5.0.1+3 more2006-05-17
CVE-2006-2435 [MEDIUM] CVE-2006-2435: Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earli Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."
nvd
CVE-2010-0774P4MEDIUMCVSS 4.3v6.0v6.0.0.1+74 more2010-05-17
CVE-2010-0774 [MEDIUM] CWE-264 CVE-2010-0774: The (1) JAX-RPC WS-Security 1.0 and (2) JAX-WS runtime implementations in IBM WebSphere Application The (1) JAX-RPC WS-Security 1.0 and (2) JAX-WS runtime implementations in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 do not properly handle WebServices PKCS#7 and PKIPath tokens, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2009-0436P4HIGHCVSS 7.2v6.0v6.0.0.1+57 more2009-02-10
CVE-2009-0436 [HIGH] CWE-264 CVE-2009-0436: The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x befo The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS), set incorrect permissions for AF_UNIX sockets, which has unknown impact and local attack vectors.
nvd
CVE-2006-6637P4MEDIUMCVSS 5.0v6.0.2.1v6.0.2.3+6 more2006-12-19
CVE-2006-6637 [MEDIUM] CWE-200 CVE-2006-6637: The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and other sensitive information via "specific requests."
nvd
CVE-2009-0892P4MEDIUMCVSS 5.5v6.1v6.1.0+25 more2009-03-31
CVE-2009-0892 [MEDIUM] CWE-287 CVE-2009-0892: The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 bef The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" related to a forced logout.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase