cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 18 of 24
CVE-2011-1314P4MEDIUMCVSS 5.0≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1314 [MEDIUM] CWE-399 CVE-2011-1314: The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) before The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (daemon hang) by performing close operations via network connections to a queue manager.
nvd
CVE-2010-2328P4MEDIUMCVSS 5.0v7.0v7.0.0.1+4 more2010-06-18
CVE-2010-2328 [MEDIUM] CVE-2010-2328: The HTTP Channel in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 allows remote attacke The HTTP Channel in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (NullPointerException) via a large amount of chunked data that uses gzip compression.
nvd
CVE-2011-1313P4MEDIUMCVSS 5.0v6.1.0v6.1.0.0+30 more2011-03-08
CVE-2011-1313 [MEDIUM] CWE-399 CVE-2011-1313: Double free vulnerability in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x Double free vulnerability in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote backend IIOP servers to cause a denial of service (S0C4 ABEND and storage corruption) by rejecting IIOP requests at opportunistic time instants, as demonstrated by requests associated with an ORB_Request::getACRWorkElementPt
nvd
CVE-2013-2967P4MEDIUMCVSS 4.3v6.1v6.1.0+70 more2013-08-21
CVE-2013-2967 [MEDIUM] CWE-79 CVE-2013-2967: Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-0783P4MEDIUMCVSS 4.3v6.1v6.1.0+45 more2010-11-09
CVE-2010-0783 [MEDIUM] CWE-79 CVE-2010-0783: Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2011-5065P4MEDIUMCVSS 4.3v6.1v6.1.0+29 more2012-01-15
CVE-2011-5065 [MEDIUM] CWE-79 CVE-2011-5065: Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0. Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.
nvd
CVE-2013-5417P4MEDIUMCVSS 4.3v7.0v7.0.0.1+37 more2013-11-18
CVE-2013-5417 [MEDIUM] CWE-79 CVE-2013-5417: Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0. Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via HTTP response data.
nvd
CVE-2012-4851P4MEDIUMCVSS 4.3≤ 8.5.0.02012-11-14
CVE-2012-4851 [MEDIUM] CWE-79 CVE-2012-4851: Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile bef Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
nvd
CVE-2012-3293P4MEDIUMCVSS 4.3v6.1.0v6.1.0.0+45 more2012-08-21
CVE-2012-3293 [MEDIUM] CWE-79 CVE-2012-3293: Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving FRAME elements, related to a cross-frame scripting (XFS) issue.
nvd
CVE-2013-4052P4MEDIUMCVSS 4.3v6.1v6.1.0+66 more2013-09-20
CVE-2013-4052 [MEDIUM] CWE-79 CVE-2013-4052: Cross-site scripting (XSS) vulnerability in the UDDI Administrative console in IBM WebSphere Applica Cross-site scripting (XSS) vulnerability in the UDDI Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-0596P4MEDIUMCVSS 4.3v6.1v6.1.0+27 more2013-09-20
CVE-2013-0596 [MEDIUM] CWE-79 CVE-2013-0596: Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-0565P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.12013-04-24
CVE-2013-0565 [MEDIUM] CWE-79 CVE-2013-0565: Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IB Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IBM WebSphere Application Server (WAS) 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted response.
nvd
CVE-2013-0458P4MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+48 more2013-01-27
CVE-2013-0458 [MEDIUM] CWE-79 CVE-2013-0458: Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2, when login security is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-0459P4MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+48 more2013-01-27
CVE-2013-0459 [MEDIUM] CWE-79 CVE-2013-0459: Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-0720P4MEDIUMCVSS 4.3v7.0v7.0.0.1+14 more2012-06-20
CVE-2012-0720 [MEDIUM] CWE-79 CVE-2012-0720: Cross-site scripting (XSS) vulnerability in the Integration Solution Console in the Administration C Cross-site scripting (XSS) vulnerability in the Integration Solution Console in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2012-0716P4MEDIUMCVSS 4.3v7.0v7.0.0.1+14 more2012-06-20
CVE-2012-0716 [MEDIUM] CWE-79 CVE-2012-0716: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2024-35153P4MEDIUMCVSS 4.8≥ 8.5.0.0, < 8.5.5.26≥ 9.0.0.0, < 9.0.5.21+1 more2024-06-27
CVE-2024-35153 [MEDIUM] CWE-79 CVE-2024-35153: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 292640.
nvd
CVE-2014-6174P4MEDIUMCVSS 4.3v7.0.0.1v7.0.0.2+46 more2014-12-18
CVE-2014-6174 [MEDIUM] CWE-254 CVE-2014-6174: IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5. IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to conduct clickjacking attacks via a crafted web site.
nvd
CVE-2024-45087P4MEDIUMCVSS 4.8v8.5v9.0+1 more2024-11-11
CVE-2024-45087 [MEDIUM] CWE-79 CVE-2024-45087: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-36000P4MEDIUMCVSS 4.8≥ 17.0.0.3, < 25.0.0.92025-08-12
CVE-2025-36000 [MEDIUM] CWE-79 CVE-2025-36000: IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-s IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd