cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 2 of 24
CVE-2010-3271P4MEDIUMCVSS 6.8PoC≤ 7.0.0.13v2.0+137 more2011-07-18
CVE-2010-3271 [MEDIUM] CWE-352 CVE-2010-3271: Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDet
nvd
CVE-2026-9072P3CRITICALCVSS 9.8v8.5v9.02026-06-22
CVE-2026-9072 [CRITICAL] CWE-94 CVE-2026-9072: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intellige IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.
nvd
CVE-2021-39031P3HIGHCVSS 8.8≥ 17.0.0.3, ≤ 22.0.0.12022-01-25
CVE-2021-39031 [HIGH] CWE-74 CVE-2021-39031: IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authentica IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.
nvd
CVE-2011-4889P3CRITICALCVSS 9.8≥ 6.1, < 6.1.0.43≥ 7.0, < 7.0.0.21+1 more2018-02-08
CVE-2011-4889 [CRITICAL] CWE-254 CVE-2011-4889: The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSph The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by l
nvd
CVE-2026-11541P3CRITICALCVSS 9.8≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+3 more2026-06-30
CVE-2026-11541 [CRITICAL] CWE-444 CVE-2026-11541: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0. IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
nvd
CVE-2026-8646P3CRITICALCVSS 9.1≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+3 more2026-06-22
CVE-2026-8646 [CRITICAL] CWE-444 CVE-2026-8646: IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose
nvd
CVE-2026-9006P3CRITICALCVSS 9.1≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-22
CVE-2026-9006 [CRITICAL] CWE-918 CVE-2026-9006: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) wi IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
nvd
CVE-2021-20353P3HIGHCVSS 8.2≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2021-02-10
CVE-2021-20353 [HIGH] CWE-611 CVE-2021-20353: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Inje IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.
nvd
CVE-2020-4949P3HIGHCVSS 8.2≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-01-26
CVE-2020-4949 [HIGH] CWE-611 CVE-2020-4949: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Inje IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
nvd
CVE-2026-11546P3CRITICALCVSS 9.8≥ 17.0.0.3, < 26.0.0.82026-06-30
CVE-2026-11546 [CRITICAL] CWE-918 CVE-2026-11546: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side re IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
nvd
CVE-2020-4362P3HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-04-10
CVE-2020-4362 [HIGH] CVE-2020-4362: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege esc IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.
nvd
CVE-2026-10845P3HIGHCVSS 7.3≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-22
CVE-2026-10845 [HIGH] CWE-287 CVE-2026-10845: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
nvd
CVE-2026-11714P3CRITICALCVSS 9.8≥ 17.0.0.3, < 26.0.0.82026-06-30
CVE-2026-11714 [CRITICAL] CWE-918 CVE-2026-11714: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side re IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
nvd
CVE-2016-5983P3HIGHCVSS 7.5v7.0v7.0.0.0+66 more2016-10-05
CVE-2016-5983 [HIGH] CWE-284 CVE-2016-5983: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11 IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.
nvd
CVE-2021-20354P3HIGHCVSS 7.5≥ 8.0.0.0, ≤ 8.0.0.15≥ 8.5.0.0, ≤ 8.5.5.19+4 more2021-02-18
CVE-2021-20354 [HIGH] CWE-22 CVE-2021-20354: IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directo IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
nvd
CVE-2005-1112P4MEDIUMCVSS 5.0PoCv5.0v5.0.1+18 more2005-05-02
CVE-2005-1112 [MEDIUM] CVE-2005-1112: IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.
nvd
CVE-2025-14917P3CRITICALCVSS 9.8≥ 17.0.0.3, < 26.0.0.42026-03-25
CVE-2025-14917 [CRITICAL] CWE-1393 CVE-2025-14917: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Serve IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.
nvd
CVE-2021-20454P3HIGHCVSS 8.2≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-04-21
CVE-2021-20454 [HIGH] CWE-611 CVE-2021-20454: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injec IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.
nvd
CVE-2021-29736P3HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-07-30
CVE-2021-29736 [HIGH] CVE-2021-29736: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated p IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.
nvd
CVE-2021-20453P3HIGHCVSS 8.2≥ 8.0.0.0, < 8.0.0.15≥ 8.5.0.0, < 8.5.5.20+4 more2021-04-20
CVE-2021-20453 [HIGH] CWE-611 CVE-2021-20453: IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase