Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 2 of 26
CVE-2026-8400P2CRITICALCVSS 9.8v8.5.0.0v9.0.0.0+2 more2026-08-05
CVE-2026-8400 [CRITICAL] CWE-470 CVE-2026-8400: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continu
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
nvd
CVE-2026-14525P3CRITICALCVSS 9.4≥ 17.0.0.3, < 26.0.0.92026-08-13
CVE-2026-14525 [CRITICAL] CWE-306 CVE-2026-14525: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Serve
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
nvd
CVE-2026-9311P3CRITICALCVSS 9.0≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-01
CVE-2026-9311 [CRITICAL] CWE-94 CVE-2026-9311: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the b
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
nvd
CVE-2013-1777P3CRITICALCVSS 10.0v3.0.0.32013-07-11
CVE-2013-1777 [CRITICAL] CWE-94 CVE-2013-1777: The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Applica
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object.
nvd
CVE-2026-11536P3HIGHCVSS 8.5≥ 8.5.0.0, < 8.5.5.29≥ 9.0.0.0, < 9.0.5.28+2 more2026-07-30
CVE-2026-11536 [HIGH] CWE-502 CVE-2026-11536: IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability i
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
nvd
CVE-2026-11541P3CRITICALCVSS 9.8≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+1 more2026-06-30
CVE-2026-11541 [CRITICAL] CWE-444 CVE-2026-11541: IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Se
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
nvd
CVE-2017-1731P3HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.43≥ 8.0.0.0, ≤ 8.0.0.14+31 more2018-01-30
CVE-2017-1731 [HIGH] CVE-2017-1731: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.
nvd
CVE-2018-1567P3CRITICALCVSS 9.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-09-07
CVE-2018-1567 [CRITICAL] CWE-502 CVE-2018-1567: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbi
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024.
nvd
CVE-2026-9072P3CRITICALCVSS 9.8v8.5v9.02026-06-22
CVE-2026-9072 [CRITICAL] CWE-94 CVE-2026-9072: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intellige
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.
nvd
CVE-2010-3271P4MEDIUMCVSS 6.8PoC≤ 7.0.0.13v2.0+137 more2011-07-18
CVE-2010-3271 [MEDIUM] CWE-352 CVE-2010-3271: Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDet
nvd
CVE-2026-8646P3CRITICALCVSS 9.1≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+3 more2026-06-22
CVE-2026-8646 [CRITICAL] CWE-444 CVE-2026-8646: IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose
nvd
CVE-2018-1904P3CRITICALCVSS 9.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-12-11
CVE-2018-1904 [CRITICAL] CWE-502 CVE-2018-1904: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbi
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.
nvd
CVE-2021-39031P3HIGHCVSS 8.8≥ 17.0.0.3, ≤ 22.0.0.12022-01-25
CVE-2021-39031 [HIGH] CWE-74 CVE-2021-39031: IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authentica
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.
nvd
CVE-2026-9006P3CRITICALCVSS 9.1≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-22
CVE-2026-9006 [CRITICAL] CWE-918 CVE-2026-9006: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) wi
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
nvd
CVE-2011-4889P3CRITICALCVSS 9.8≥ 6.1, < 6.1.0.43≥ 7.0, < 7.0.0.21+1 more2018-02-08
CVE-2011-4889 [CRITICAL] CWE-254 CVE-2011-4889: The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSph
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by l
nvd
CVE-2026-14529P3CRITICALCVSS 9.8≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+3 more2026-07-29
CVE-2026-14529 [CRITICAL] CWE-306 CVE-2026-14529: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
nvd
CVE-2026-11546P3CRITICALCVSS 9.8≥ 17.0.0.3, < 26.0.0.82026-06-30
CVE-2026-11546 [CRITICAL] CWE-918 CVE-2026-11546: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side re
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
nvd
CVE-2021-20353P3HIGHCVSS 8.2≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2021-02-10
CVE-2021-20353 [HIGH] CWE-611 CVE-2021-20353: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Inje
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.
nvd
CVE-2020-4949P3HIGHCVSS 8.2≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-01-26
CVE-2020-4949 [HIGH] CWE-611 CVE-2020-4949: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Inje
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
nvd
CVE-2026-11714P3CRITICALCVSS 9.8≥ 17.0.0.3, < 26.0.0.82026-06-30
CVE-2026-11714 [CRITICAL] CWE-918 CVE-2026-11714: IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
nvd