Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 20 of 26
CVE-2015-0106P4MEDIUMCVSS 4.3v7.1v7.2+5 more2015-03-24
CVE-2015-0106 [MEDIUM] CWE-79 CVE-2015-0106: Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2024-22329P4MEDIUMCVSS 4.3≥ 8.5.0.0, < 8.5.5.26≥ 9.0.0.0, < 9.0.5.20+2 more2024-04-17
CVE-2024-22329 [MEDIUM] CWE-918 CVE-2024-22329: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to conduct the SSRF attack. X-Force ID: 279951.
nvd
CVE-2011-1355P4MEDIUMCVSS 5.8v6.1v6.1.0+42 more2011-07-19
CVE-2011-1355 [MEDIUM] CWE-20 CVE-2011-1355: Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 be
Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage parameter.
nvd
CVE-2001-0824P4HIGHCVSS 7.5v3.0.2v3.52001-12-06
CVE-2001-0824 [HIGH] CVE-2001-0824: Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to exec
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
nvd
CVE-2009-0435P4MEDIUMCVSS 5.0v6.1.0v6.1.0.0+23 more2009-02-10
CVE-2009-0435 [MEDIUM] CVE-2009-0435: Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Mes
Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Message Service (JMS) component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.17 on AIX 5.3 allows attackers to cause a denial of service (daemon crash) via vectors related to the aio_getioev2 and getEvent methods.
nvd
CVE-2011-1314P4MEDIUMCVSS 5.0≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1314 [MEDIUM] CWE-399 CVE-2011-1314: The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) before
The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (daemon hang) by performing close operations via network connections to a queue manager.
nvd
CVE-2010-2328P4MEDIUMCVSS 5.0v7.0v7.0.0.1+4 more2010-06-18
CVE-2010-2328 [MEDIUM] CVE-2010-2328: The HTTP Channel in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 allows remote attacke
The HTTP Channel in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (NullPointerException) via a large amount of chunked data that uses gzip compression.
nvd
CVE-2011-1313P4MEDIUMCVSS 5.0v6.1.0v6.1.0.0+30 more2011-03-08
CVE-2011-1313 [MEDIUM] CWE-399 CVE-2011-1313: Double free vulnerability in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x
Double free vulnerability in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote backend IIOP servers to cause a denial of service (S0C4 ABEND and storage corruption) by rejecting IIOP requests at opportunistic time instants, as demonstrated by requests associated with an ORB_Request::getACRWorkElementPt
nvd
CVE-2013-2967P4MEDIUMCVSS 4.3v6.1v6.1.0+70 more2013-08-21
CVE-2013-2967 [MEDIUM] CWE-79 CVE-2013-2967: Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-0783P4MEDIUMCVSS 4.3v6.1v6.1.0+45 more2010-11-09
CVE-2010-0783 [MEDIUM] CWE-79 CVE-2010-0783: Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2011-5065P4MEDIUMCVSS 4.3v6.1v6.1.0+29 more2012-01-15
CVE-2011-5065 [MEDIUM] CWE-79 CVE-2011-5065: Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.
nvd
CVE-2013-5417P4MEDIUMCVSS 4.3v7.0v7.0.0.1+37 more2013-11-18
CVE-2013-5417 [MEDIUM] CWE-79 CVE-2013-5417: Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via HTTP response data.
nvd
CVE-2012-4851P4MEDIUMCVSS 4.3≤ 8.5.0.02012-11-14
CVE-2012-4851 [MEDIUM] CWE-79 CVE-2012-4851: Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile bef
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
nvd
CVE-2012-3293P4MEDIUMCVSS 4.3v6.1.0v6.1.0.0+45 more2012-08-21
CVE-2012-3293 [MEDIUM] CWE-79 CVE-2012-3293: Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving FRAME elements, related to a cross-frame scripting (XFS) issue.
nvd
CVE-2014-6167P4MEDIUMCVSS 4.3v7.0.0.1v7.0.0.2+46 more2014-12-18
CVE-2014-6167 [MEDIUM] CWE-79 CVE-2014-6167: Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application S
Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-4052P4MEDIUMCVSS 4.3v6.1v6.1.0+66 more2013-09-20
CVE-2013-4052 [MEDIUM] CWE-79 CVE-2013-4052: Cross-site scripting (XSS) vulnerability in the UDDI Administrative console in IBM WebSphere Applica
Cross-site scripting (XSS) vulnerability in the UDDI Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-0596P4MEDIUMCVSS 4.3v6.1v6.1.0+27 more2013-09-20
CVE-2013-0596 [MEDIUM] CWE-79 CVE-2013-0596: Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-0542P4MEDIUMCVSS 4.3≤ 6.1.0.45v6.1.0+52 more2013-04-24
CVE-2013-0542 [MEDIUM] CWE-79 CVE-2013-0542: Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via crafted field values.
nvd
CVE-2013-0565P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.12013-04-24
CVE-2013-0565 [MEDIUM] CWE-79 CVE-2013-0565: Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IB
Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IBM WebSphere Application Server (WAS) 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted response.
nvd
CVE-2013-0458P4MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+48 more2013-01-27
CVE-2013-0458 [MEDIUM] CWE-79 CVE-2013-0458: Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2, when login security is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd