cbcvebase.

Ibm Websphere Application Server vulnerabilities

477 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
477
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL63HIGH109MEDIUM265LOW40

Vulnerabilities

Page 21 of 24
CVE-2009-0856P4MEDIUMCVSS 4.3v6.1v6.1.0.0+22 more2009-03-09
CVE-2009-0856 [MEDIUM] CWE-79 CVE-2009-0856: Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Applicat Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, and 6.1 before 6.1.0.23 on z/OS, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2007-5798P4MEDIUMCVSS 4.3≤ 6.1.0.122007-11-03
CVE-2007-5798 [MEDIUM] CWE-79 CVE-2007-5798: Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user cons Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to inject arbitrary web script or HTML via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
nvd
CVE-2010-0779P4MEDIUMCVSS 4.3v6.1v6.1.0+52 more2010-06-24
CVE-2010-0779 [MEDIUM] CWE-79 CVE-2010-0779: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-0778P4MEDIUMCVSS 4.3v6.1v6.1.0+24 more2010-06-24
CVE-2010-0778 [MEDIUM] CWE-79 CVE-2010-0778: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-0707P4MEDIUMCVSS 4.3v7.22012-02-23
CVE-2012-0707 [MEDIUM] CWE-79 CVE-2012-0707: Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attacke Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attackers to inject arbitrary web script or HTML via crafted text input to a coach that is configured with a document attachment control section.
nvd
CVE-2007-1944P4MEDIUMCVSS 5.0≤ 6.1.0.12007-04-11
CVE-2007-1944 [MEDIUM] CWE-119 CVE-2007-1944: The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attac The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.
nvd
CVE-2006-4222P4MEDIUMCVSS 5.0≤ 6.0.2.11v6.0.2+5 more2006-08-18
CVE-2006-4222 [MEDIUM] CVE-2006-4222: Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspec Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspecified vectors and impact, including (1) an "authority problem" in ThreadIdentitySupport as identified by PK25199, and "Potential security exposure" issues as identified by (2) PK22747, (3) PK24334, (4) PK25740, and (5) PK26123.
nvd
CVE-2011-1318P4MEDIUMCVSS 5.0≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1318 [MEDIUM] CWE-399 CVE-2011-1318: Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) compon Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by accessing a JSP page of an application that is repeatedly stopped and restarted.
nvd
CVE-2006-7164P4MEDIUMCVSS 4.3v5.0.1v5.0.2+16 more2007-03-20
CVE-2006-7164 [MEDIUM] CVE-2006-7164: SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does n SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.
nvd
CVE-2008-7274P4MEDIUMCVSS 4.3v6.1.0.92011-02-15
CVE-2008-7274 [MEDIUM] CWE-20 CVE-2008-7274: IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2) providing an empty password.
nvd
CVE-2011-1209P4MEDIUMCVSS 4.3v6.1.0v6.1.0.0+44 more2011-05-04
CVE-2011-1209 [MEDIUM] CWE-310 CVE-2011-1209: IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Se IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Security XML encryption algorithm, which makes it easier for remote attackers to obtain plaintext data from a (1) JAX-RPC or (2) JAX-WS Web Services request via unspecified vectors related to a "decryption attack."
nvd
CVE-2011-1312P4MEDIUMCVSS 4.0v6.1.0v6.1.0.0+28 more2011-03-08
CVE-2011-1312 [MEDIUM] CWE-264 CVE-2011-1312: The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0. The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.
nvd
CVE-2009-0506P4MEDIUMCVSS 6.2v5.1.0v6.0.2+11 more2009-02-25
CVE-2009-0506 [MEDIUM] CVE-2009-0506: Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) mul
nvd
CVE-2006-4137P4MEDIUMCVSS 5.0v6.0v6.0.0.1+14 more2006-08-14
CVE-2006-4137 [MEDIUM] CVE-2006-4137: IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.
nvd
CVE-2013-4006P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+2 more2013-11-18
CVE-2013-4006 [MEDIUM] CWE-310 CVE-2013-4006: IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.
nvd
CVE-2005-4413P4MEDIUMCVSS 4.3v6.02005-12-20
CVE-2005-4413 [MEDIUM] CVE-2005-4413: Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application S Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application Server 6 allow remote attackers to inject arbitrary web script or HTML via the (1) E-mail address field to (a) PlantsByWebSphere/login.jsp, (2) message field to (b) TechnologySample/BulletinBoard Script, (3) Email address field to (c) TechnologySamples/Subscript
nvd
CVE-2011-1308P4MEDIUMCVSS 4.3≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1308 [MEDIUM] CWE-79 CVE-2011-1308: Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2011-1319P4MEDIUMCVSS 4.0v6.1.0v6.1.0.0+30 more2011-03-08
CVE-2011-1319 [MEDIUM] CWE-399 CVE-2011-1319: The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x bef The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote authenticated users to cause a denial of service (memory consumption) by using a Lightweight Third-Party Authentication (LTPA) token for authentication.
nvd
CVE-2007-5799P4MEDIUMCVSS 4.3≤ 6.1.0.122007-11-03
CVE-2007-5799 [MEDIUM] CWE-352 CVE-2007-5799: Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI us Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
nvd
CVE-2015-5004P4MEDIUMCVSS 4.0v8.0.0.0v8.0.0.1+21 more2015-12-15
CVE-2015-5004 [MEDIUM] CWE-200 CVE-2015-5004: The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8 The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase