Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 19 of 26
CVE-2012-2190P4MEDIUMCVSS 5.0v6.1.0v6.1.0.0+45 more2012-08-21
CVE-2012-2190 [MEDIUM] CWE-310 CVE-2012-2190: IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server
IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1, allows remote attackers to cause a denial of service (daemon crash) via a crafted ClientHello message in the TLS Handshake Protocol.
nvd
CVE-2014-0891P4MEDIUMCVSS 5.0v7.0v7.0.0.1+40 more2014-06-28
CVE-2014-0891 [MEDIUM] CWE-200 CVE-2014-0891: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information by leveraging incorrect request handling by the (1) Proxy or (2) ODR server.
nvd
CVE-2009-1900P4MEDIUMCVSS 5.0≤ 6.0.2.33v6.0.2+31 more2009-06-03
CVE-2009-1900 [MEDIUM] CWE-200 CVE-2009-1900: The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (
The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5, when tracing is enabled, allow remote attackers to obtain sensitive information via unspecified use of the wsadmin scripting tool.
nvd
CVE-2011-1322P4MEDIUMCVSS 5.0v6.1.0v6.1.0.0+31 more2011-03-08
CVE-2011-1322 [MEDIUM] CWE-399 CVE-2011-1322: The SOAP with Attachments API for Java (SAAJ) implementation in the Web Services component in IBM We
The SOAP with Attachments API for Java (SAAJ) implementation in the Web Services component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via encrypted SOAP messages.
nvd
CVE-2010-0775P4MEDIUMCVSS 5.0v6.0v6.0.0.1+74 more2010-05-17
CVE-2010-0775 [MEDIUM] CWE-399 CVE-2010-0775: Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (memory consumption and daemon crash) via a crafted request, related to the nodeagent and Deployment Manager components.
nvd
CVE-2010-0776P4MEDIUMCVSS 5.0v6.0v6.0.0.1+74 more2010-05-17
CVE-2010-0776 [MEDIUM] CWE-20 CVE-2010-0776: The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle chunked transfer encoding during a call to response.sendRedirect, which allows remote attackers to cause a denial of service via a GET request.
nvd
CVE-2009-0438P4MEDIUMCVSS 5.0v7.02009-02-10
CVE-2009-0438 [MEDIUM] CVE-2009-0438: IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412.
nvd
CVE-2013-0544P4MEDIUMCVSS 4.0v6.1.0.0v6.1.0.1+51 more2013-04-24
CVE-2013-0544 [MEDIUM] CWE-22 CVE-2013-0544: Directory traversal vulnerability in the Administrative Console in IBM WebSphere Application Server
Directory traversal vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux and UNIX allows remote authenticated users to modify data via unspecified vectors.
nvd
CVE-2008-4284P4MEDIUMCVSS 5.8v5.0v5.0.0+106 more2009-02-10
CVE-2008-4284 [MEDIUM] CWE-59 CVE-2008-4284: Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (
Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x before 6.0.2.33, and 6.1.x before 6.1.0.23 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage feature.
nvd
CVE-2009-0432P4MEDIUMCVSS 5.0v6.1.0.1v6.1.0.2+8 more2009-02-10
CVE-2009-0432 [MEDIUM] CWE-16 CVE-2009-0432: The installation process for the File Transfer servlet in the System Management/Repository component
The installation process for the File Transfer servlet in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19 does not enable the secure version, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2009-1898P4MEDIUMCVSS 5.0≤ 6.0.2.33v6.0.2+31 more2009-06-03
CVE-2009-1898 [MEDIUM] CWE-200 CVE-2009-1898: The secure login page in the Administrative Console component in IBM WebSphere Application Server (W
The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.
nvd
CVE-2008-5411P4MEDIUMCVSS 5.0≤ 7.02008-12-10
CVE-2008-5411 [MEDIUM] CWE-310 CVE-2008-5411: IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," whic
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2008-3236P4MEDIUMCVSS 5.0v5.1.0v5.1.1+18 more2008-07-21
CVE-2008-3236 [MEDIUM] CWE-310 CVE-2008-3236: Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere
Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allows attackers to obtain sensitive information via vectors related to "previously encrypted properties" that are not encrypted.
nvd
CVE-2009-2091P4MEDIUMCVSS 5.0v7.0v7.0.0.1+2 more2009-08-13
CVE-2009-2091 [MEDIUM] CWE-264 CVE-2009-2091: The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.
The System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 on z/OS uses weak file permissions for new applications, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2012-2170P4MEDIUMCVSS 4.3v7.0v7.0.0.1+14 more2012-06-20
CVE-2012-2170 [MEDIUM] CWE-264 CVE-2012-2170: The Application Snoop Servlet in IBM WebSphere Application Server 7.0 before 7.0.0.23 does not prope
The Application Snoop Servlet in IBM WebSphere Application Server 7.0 before 7.0.0.23 does not properly restrict access, which allows remote attackers to obtain sensitive client and request information via a direct request.
nvd
CVE-2013-6325P4MEDIUMCVSS 4.3v8.0.0.0v8.0.0.1+38 more2014-01-16
CVE-2013-6325 [MEDIUM] CWE-20 CVE-2013-6325: IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2
IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote attackers to cause a denial of service (resource consumption) via a crafted request to a web services endpoint.
nvd
CVE-2014-0965P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+35 more2014-08-22
CVE-2014-0965 [MEDIUM] CWE-200 CVE-2014-0965: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted SOAP response.
nvd
CVE-2013-0461P4MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+48 more2013-01-27
CVE-2013-0461 [MEDIUM] CWE-79 CVE-2013-0461: Cross-site scripting (XSS) vulnerability in the virtual member manager (VMM) administrative console
Cross-site scripting (XSS) vulnerability in the virtual member manager (VMM) administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2016-0377P4MEDIUMCVSS 4.3v7.0.0.0v7.0.0.1+64 more2016-10-22
CVE-2016-0377 [MEDIUM] CWE-200 CVE-2016-0377: The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x befo
The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2018-1902P4MEDIUMCVSS 4.3fixed in 19.0.0.3≥ 7.0.0.0, ≤ 7.0.0.45+7 more2019-03-11
CVE-2018-1902 [MEDIUM] CWE-200 CVE-2018-1902: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof conne
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof connection information which could be used to launch further attacks against the system. IBM X-Force ID: 152531.
nvd