cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 19 of 24
CVE-2010-2327P4MEDIUMCVSS 4.3v6.0v6.0.0.1+52 more2010-06-18
CVE-2010-2327 [MEDIUM] CWE-20 CVE-2010-2327: mod_ibm_ssl in IBM HTTP Server 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11, as mod_ibm_ssl in IBM HTTP Server 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11, as used in IBM WebSphere Application Server (WAS) on z/OS, does not properly handle a large HTTP request body in uploading over SSL, which might allow remote attackers to cause a denial of service (daemon fail) via an upload.
nvd
CVE-2014-0957P4MEDIUMCVSS 4.3v7.22014-07-18
CVE-2014-0957 [MEDIUM] CWE-79 CVE-2014-0957: Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebS Cross-site scripting (XSS) vulnerability in IBM Business Process Manager 7.5 through 8.5.5, and WebSphere Lombardi Edition 7.2, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a service failure.
nvd
CVE-2020-4329P4MEDIUMCVSS 4.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+7 more2020-04-28
CVE-2020-4329 [MEDIUM] CVE-2020-4329: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allo IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenticated attacker to obtain sensitive information, caused by improper parameter checking. This could be exploited to conduct spoofing attacks. IBM X-Force ID: 177841.
nvd
CVE-2006-1093P4MEDIUMCVSS 6.4v5.0.2v5.0.2.1+23 more2006-03-09
CVE-2006-1093 [MEDIUM] CVE-2006-1093: Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 all Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 allows remote attackers to obtain sensitive information via unknown attack vectors, which causes JSP source code to be revealed.
nvd
CVE-2013-0540P4LOWCVSS 3.5v8.5.0.0v8.5.0.12013-04-24
CVE-2013-0540 [LOW] CWE-287 CVE-2013-0540: IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.
nvd
CVE-2007-3397P4MEDIUMCVSS 5.0v6.0.2v6.0.2.1+18 more2007-06-26
CVE-2007-3397 [MEDIUM] CVE-2007-3397: The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0. The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.
nvd
CVE-2005-0425P4MEDIUMCVSS 5.0v5.0v5.1.0+1 more2005-05-02
CVE-2005-0425 [MEDIUM] CVE-2005-0425: Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.
nvd
CVE-2006-2434P4MEDIUMCVSS 5.0v5.1.12006-05-17
CVE-2006-2434 [MEDIUM] CVE-2006-2434: Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mo Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace.
nvd
CVE-2008-2550P4MEDIUMCVSS 5.0≤ 6.1.0.16v6.1+17 more2008-06-04
CVE-2008-2550 [MEDIUM] CVE-2008-2550: Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.17 has unknown impact and attack vectors related to an attribute in the SOAP security header.
nvd
CVE-2008-5413P4MEDIUMCVSS 5.0≤ 7.02008-12-10
CVE-2008-5413 [MEDIUM] CWE-200 CVE-2008-5413: PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 befor PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2009-0434.
nvd
CVE-2005-4834P4MEDIUMCVSS 5.0v5.0.2.5v5.0.2.6+11 more2005-12-31
CVE-2005-4834 [MEDIUM] CVE-2005-4834: IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP source code and other sensitive information, related to incorrect request processing by the web container.
nvd
CVE-2012-0717P4LOWCVSS 2.6v7.0v7.0.0.1+14 more2012-06-20
CVE-2012-0717 [LOW] CWE-287 CVE-2012-0717: IBM WebSphere Application Server 7.0 before 7.0.0.23, when a certain SSLv2 configuration with client IBM WebSphere Application Server 7.0 before 7.0.0.23, when a certain SSLv2 configuration with client authentication is used, allows remote attackers to bypass X.509 client-certificate authentication via unspecified vectors.
nvd
CVE-2011-1316P4MEDIUMCVSS 5.0≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1316 [MEDIUM] CWE-399 CVE-2011-1316: The Session Initiation Protocol (SIP) Proxy in the HTTP Transport component in IBM WebSphere Applica The Session Initiation Protocol (SIP) Proxy in the HTTP Transport component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (worker thread exhaustion and UDP messaging outage) by sending many UDP messages.
nvd
CVE-2006-3231P4MEDIUMCVSS 4.3v2.0v3.0+48 more2006-06-27
CVE-2006-3231 [MEDIUM] CVE-2006-3231: Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServin Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."
nvd
CVE-2014-3022P4MEDIUMCVSS 4.3v8.0.0.0v8.0.0.1+35 more2014-08-22
CVE-2014-3022 [MEDIUM] CWE-200 CVE-2014-3022: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition.
nvd
CVE-2011-0315P4MEDIUMCVSS 4.3v6.1v6.1.0+32 more2011-01-12
CVE-2011-0315 [MEDIUM] CWE-79 CVE-2011-0315: Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebS Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to the lack of an error page for an application.
nvd
CVE-2014-0896P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+3 more2014-05-01
CVE-2014-0896 [MEDIUM] CWE-200 CVE-2014-0896: IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information via a crafted request.
nvd
CVE-2011-1362P4MEDIUMCVSS 4.3v6.1v6.1.0+43 more2012-01-15
CVE-2011-1362 [MEDIUM] CVE-2011-1362: Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for C
nvd
CVE-2009-2748P4MEDIUMCVSS 4.3v6.1.0v6.1.0.0+21 more2011-10-30
CVE-2009-2748 [MEDIUM] CWE-79 CVE-2009-2748: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-2325P4MEDIUMCVSS 4.3≤ 7.0.0.10v7.0+9 more2010-06-18
CVE-2010-2325 [MEDIUM] CWE-79 CVE-2010-2325: Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."
nvd
Ibm Websphere Application Server vulnerabilities | cvebase