Ibm Websphere Application Server vulnerabilities
477 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
477
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL63HIGH109MEDIUM265LOW40
Vulnerabilities
Page 20 of 24
CVE-2010-0768P4MEDIUMCVSS 4.3≤ 6.0.2.39v6.0.2+41 more2010-04-01
CVE-2010-0768 [MEDIUM] CWE-79 CVE-2010-0768: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the URI.
nvd
CVE-2009-2742P4MEDIUMCVSS 4.3v6.1v6.1.0.1+13 more2009-09-21
CVE-2009-2742 [MEDIUM] CWE-79 CVE-2009-2742: Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6
Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input.
nvd
CVE-2009-0899P4MEDIUMCVSS 4.3≥ 6.1, ≤ 6.1.0.24≥ 7.0, ≤ 7.0.0.42009-06-03
CVE-2009-0899 [MEDIUM] CWE-264 CVE-2009-0899: IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere P
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which a
nvd
CVE-2024-45073P4MEDIUMCVSS 4.8v8.5v9.0+1 more2024-09-30
CVE-2024-45073 [MEDIUM] CWE-79 CVE-2024-45073: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vuln
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-45071P4MEDIUMCVSS 4.8≥ 8.5.0.0, ≤ 8.5.5.26≥ 9.0.0.0, ≤ 9.0.5.21+1 more2024-10-16
CVE-2024-45071 [MEDIUM] CWE-79 CVE-2024-45071: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vuln
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2014-0857P4MEDIUMCVSS 4.0v8.5.0.0v8.5.0.1+13 more2014-05-01
CVE-2014-0857 [MEDIUM] CWE-200 CVE-2014-0857: The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x be
The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.
nvd
CVE-2015-0174P4MEDIUMCVSS 4.0v8.5.0.0v8.5.0.1+6 more2015-04-27
CVE-2015-0174 [MEDIUM] CWE-200 CVE-2015-0174: The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not proper
The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-4758P4MEDIUMCVSS 4.0v7.2v7.2.0.1+4 more2014-09-04
CVE-2014-4758 [MEDIUM] CWE-264 CVE-2014-4758: IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow re
IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.
nvd
CVE-2013-5414P4LOWCVSS 3.5v7.0v7.0.0.1+37 more2013-11-18
CVE-2013-5414 [LOW] CWE-264 CVE-2013-5414: The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 befor
The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a m
nvd
CVE-2007-4833P4MEDIUMCVSS 5.0≤ 6.1.0.92007-09-12
CVE-2007-4833 [MEDIUM] CVE-2007-4833: Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before
Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK44789.
nvd
CVE-2006-4223P4MEDIUMCVSS 5.0≤ 6.0.2.11v6.0.2+5 more2006-08-18
CVE-2006-4223 [MEDIUM] CVE-2006-4223: IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain
IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileServingEnabled to true or ExtendedDocumentRoot is used to place a JSP outside a WAR.file; (3) the First Failure Data Capture
nvd
CVE-2006-7166P4MEDIUMCVSS 5.0v5.0v5.0.1+32 more2007-03-20
CVE-2006-7166 [MEDIUM] CVE-2006-7166: IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP sou
IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a specific JSP URL."
nvd
CVE-2008-4285P4MEDIUMCVSS 5.0v6.1v6.1.0+10 more2009-02-17
CVE-2008-4285 [MEDIUM] CWE-399 CVE-2008-4285: Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet
Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19, when a component statistic is enabled, allows attackers to cause a denial of service (daemon crash) via vectors related to "a gradual degradation in performan
nvd
CVE-2011-1317P4MEDIUMCVSS 5.0v6.1.0v6.1.0.0+31 more2011-03-08
CVE-2011-1317 [MEDIUM] CWE-399 CVE-2011-1317: Memory leak in com.ibm.ws.jsp.runtime.WASJSPStrBufferImpl in the JavaServer Pages (JSP) component in
Memory leak in com.ibm.ws.jsp.runtime.WASJSPStrBufferImpl in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by sending many JSP requests that trigger large responses.
nvd
CVE-2011-1315P4MEDIUMCVSS 5.0≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1315 [MEDIUM] CWE-399 CVE-2011-1315: Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows
Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via network connections associated with a NULL return value from a synchronous JMS receive call.
nvd
CVE-2010-2323P4MEDIUMCVSS 5.0≤ 7.0.0.10v7.0+9 more2010-06-18
CVE-2010-2323 [MEDIUM] CWE-200 CVE-2010-2323: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain s
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_create.log file that is associated with profile creation by the BBOWWPFx job and the zPMT.
nvd
CVE-2007-3265P4MEDIUMCVSS 4.3≤ 6.1.0.72007-06-19
CVE-2007-3265 [MEDIUM] CVE-2007-3265: Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Serve
Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-4220P4MEDIUMCVSS 4.3v7.0v7.0.0.1+11 more2010-11-09
CVE-2010-4220 [MEDIUM] CWE-79 CVE-2010-4220: Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Co
Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Console component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."
nvd
CVE-2005-2091P4MEDIUMCVSS 4.3v5.0v5.1.02005-07-05
CVE-2005-2091 [MEDIUM] CVE-2005-2091: IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web appl
IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the recei
nvd
CVE-2010-0784P4MEDIUMCVSS 4.3v7.0v7.0.0.1+11 more2010-11-09
CVE-2010-0784 [MEDIUM] CWE-79 CVE-2010-0784: Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd