Ibm Websphere Application Server vulnerabilities
451 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
451
CISA KEV
1
actively exploited
Public exploits
13
Exploited in wild
2
Severity breakdown
CRITICAL53HIGH95MEDIUM263LOW40
Vulnerabilities
Page 2 of 23
CVE-2025-36000MEDIUMCVSS 4.8≥ 17.0.0.3, < 25.0.0.92025-08-12
CVE-2025-36000 [MEDIUM] CWE-79 CVE-2025-36000: IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8
is vulnerable to stored cross-s
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8
is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-56339HIGHCVSS 7.5≥ 17.0.0.3, ≤ 25.0.0.7v9.0.0.0+1 more2025-08-07
CVE-2024-56339 [HIGH] CWE-650 CVE-2024-56339: IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.
nvd
CVE-2025-36097HIGHCVSS 7.5≥ 9.0.0.0, < 9.0.5.24≥ 17.0.0.3, < 25.0.0.8+1 more2025-07-16
CVE-2025-36097 [HIGH] CWE-121 CVE-2025-36097: IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
nvd
CVE-2025-36038CRITICALCVSS 9.8≥ 8.5, < 8.5.5.28≥ 9.0, < 9.0.5.25+2 more2025-06-25
CVE-2025-36038 [CRITICAL] CWE-502 CVE-2025-36038: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
nvd
CVE-2025-33104HIGHCVSS 7.6≥ 8.5, < 8.5.5.28≥ 9.0, < 9.0.5.24+1 more2025-05-14
CVE-2025-33104 [HIGH] CWE-79 CVE-2025-33104: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-27907LOWCVSS 2.7≥ 8.5, < 8.5.5.28≥ 9.0, < 9.0.5.24+2 more2025-04-22
CVE-2025-27907 [LOW] CWE-918 CVE-2025-27907: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). Th
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2024-45087MEDIUMCVSS 4.8v8.5v9.0+1 more2024-11-11
CVE-2024-45087 [MEDIUM] CWE-79 CVE-2024-45087: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-45086MEDIUMCVSS 5.5≥ 8.5.0.0, < 8.5.5.27≥ 9.0.0.0, < 9.0.5.22+1 more2024-11-04
CVE-2024-45086 [MEDIUM] CWE-611 CVE-2024-45086: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
nvd
CVE-2024-45072MEDIUMCVSS 5.5≥ 8.5.0.0, ≤ 8.5.5.26≥ 9.0.0.0, ≤ 9.0.5.21+1 more2024-10-16
CVE-2024-45072 [MEDIUM] CWE-611 CVE-2024-45072: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
nvd
CVE-2024-45071MEDIUMCVSS 4.8≥ 8.5.0.0, ≤ 8.5.5.26≥ 9.0.0.0, ≤ 9.0.5.21+1 more2024-10-16
CVE-2024-45071 [MEDIUM] CWE-79 CVE-2024-45071: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vuln
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-45085HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.27v8.52024-10-15
CVE-2024-45085 [HIGH] CWE-754 CVE-2024-45085: IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurati
IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker could exploit this vulnerability to cause an error resulting in a denial of service.
nvd
CVE-2024-45073MEDIUMCVSS 4.8v8.5v9.0+1 more2024-09-30
CVE-2024-45073 [MEDIUM] CWE-79 CVE-2024-45073: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vuln
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-50314HIGHCVSS 7.5≥ 17.0.0.3, ≤ 24.0.0.82024-08-14
CVE-2023-50314 [HIGH] CWE-295 CVE-2023-50314: IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with acce
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274713.
nvd
CVE-2023-50315MEDIUMCVSS 5.9v8.5.0.0v9.0.0.0+1 more2024-08-14
CVE-2023-50315 [MEDIUM] CWE-295 CVE-2023-50315: IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to c
IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274714.
nvd
CVE-2024-35154HIGHCVSS 7.2≥ 8.5.0.0, ≤ 8.5.5.25≥ 9.0.0.0, ≤ 9.0.5.20+1 more2024-07-09
CVE-2024-35154 [HIGH] CWE-250 CVE-2024-35154: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has au
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.
nvd
CVE-2024-35153MEDIUMCVSS 4.8≥ 8.5.0.0, < 8.5.5.26≥ 9.0.0.0, < 9.0.5.21+1 more2024-06-27
CVE-2024-35153 [MEDIUM] CWE-79 CVE-2024-35153: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 292640.
nvd
CVE-2024-37532HIGHCVSS 8.8v8.5.0.0v9.0.0.0+1 more2024-06-20
CVE-2024-37532 [HIGH] CWE-347 CVE-2024-37532: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.
nvd
CVE-2024-25026HIGHCVSS 7.5≥ 8.5.0.0, ≤ 8.5.5.25≥ 9.0.0.0, ≤ 9.0.5.19+2 more2024-04-25
CVE-2024-25026 [HIGH] CWE-770 CVE-2024-25026: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 281516.
nvd
CVE-2024-22354HIGHCVSS 7.0≥ 8.5.0.0, < 8.5.5.26≥ 9.0.0.0, < 9.0.5.20+2 more2024-04-17
CVE-2024-22354 [HIGH] CWE-611 CVE-2024-22354: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forg
nvd
CVE-2024-22329MEDIUMCVSS 4.3≥ 8.5.0.0, < 8.5.5.26≥ 9.0.0.0, < 9.0.5.20+2 more2024-04-17
CVE-2024-22329 [MEDIUM] CWE-918 CVE-2024-22329: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to conduct the SSRF attack. X-Force ID: 279951.
nvd