cbcvebase.

Ibm Websphere Application Server vulnerabilities

517 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42

Vulnerabilities

Page 22 of 26
CVE-2006-3231P4MEDIUMCVSS 4.3v2.0v3.0+48 more2006-06-27
CVE-2006-3231 [MEDIUM] CVE-2006-3231: Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServin Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."
nvd
CVE-2014-3022P4MEDIUMCVSS 4.3v8.0.0.0v8.0.0.1+35 more2014-08-22
CVE-2014-3022 [MEDIUM] CWE-200 CVE-2014-3022: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition.
nvd
CVE-2011-0315P4MEDIUMCVSS 4.3v6.1v6.1.0+32 more2011-01-12
CVE-2011-0315 [MEDIUM] CWE-79 CVE-2011-0315: Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebS Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to the lack of an error page for an application.
nvd
CVE-2014-0896P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+3 more2014-05-01
CVE-2014-0896 [MEDIUM] CWE-200 CVE-2014-0896: IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information via a crafted request.
nvd
CVE-2011-1362P4MEDIUMCVSS 4.3v6.1v6.1.0+43 more2012-01-15
CVE-2011-1362 [MEDIUM] CVE-2011-1362: Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for C
nvd
CVE-2009-2748P4MEDIUMCVSS 4.3v6.1.0v6.1.0.0+21 more2011-10-30
CVE-2009-2748 [MEDIUM] CWE-79 CVE-2009-2748: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-0768P4MEDIUMCVSS 4.3≤ 6.0.2.39v6.0.2+41 more2010-04-01
CVE-2010-0768 [MEDIUM] CWE-79 CVE-2010-0768: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the URI.
nvd
CVE-2009-2742P4MEDIUMCVSS 4.3v6.1v6.1.0.1+13 more2009-09-21
CVE-2009-2742 [MEDIUM] CWE-79 CVE-2009-2742: Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6 Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input.
nvd
CVE-2009-0899P4MEDIUMCVSS 4.3≥ 6.1, ≤ 6.1.0.24≥ 7.0, ≤ 7.0.0.42009-06-03
CVE-2009-0899 [MEDIUM] CWE-264 CVE-2009-0899: IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere P IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which a
nvd
CVE-2024-45073P4MEDIUMCVSS 4.8v8.5v9.0+1 more2024-09-30
CVE-2024-45073 [MEDIUM] CWE-79 CVE-2024-45073: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vuln IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-45071P4MEDIUMCVSS 4.8≥ 8.5.0.0, ≤ 8.5.5.26≥ 9.0.0.0, ≤ 9.0.5.21+1 more2024-10-16
CVE-2024-45071 [MEDIUM] CWE-79 CVE-2024-45071: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vuln IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2014-0857P4MEDIUMCVSS 4.0v8.5.0.0v8.5.0.1+13 more2014-05-01
CVE-2014-0857 [MEDIUM] CWE-200 CVE-2014-0857: The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x be The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.
nvd
CVE-2015-0174P4MEDIUMCVSS 4.0v8.5.0.0v8.5.0.1+6 more2015-04-27
CVE-2015-0174 [MEDIUM] CWE-200 CVE-2015-0174: The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not proper The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-4758P4MEDIUMCVSS 4.0v7.2v7.2.0.1+4 more2014-09-04
CVE-2014-4758 [MEDIUM] CWE-264 CVE-2014-4758: IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow re IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.
nvd
CVE-2013-5414P4LOWCVSS 3.5v7.0v7.0.0.1+37 more2013-11-18
CVE-2013-5414 [LOW] CWE-264 CVE-2013-5414: The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 befor The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a m
nvd
CVE-2006-2434P4MEDIUMCVSS 5.0v5.1.12006-05-17
CVE-2006-2434 [MEDIUM] CVE-2006-2434: Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mo Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace.
nvd
CVE-2007-4833P4MEDIUMCVSS 5.0≤ 6.1.0.92007-09-12
CVE-2007-4833 [MEDIUM] CVE-2007-4833: Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK44789.
nvd
CVE-2006-4222P4MEDIUMCVSS 5.0≤ 6.0.2.11v6.0.2+5 more2006-08-18
CVE-2006-4222 [MEDIUM] CVE-2006-4222: Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspec Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspecified vectors and impact, including (1) an "authority problem" in ThreadIdentitySupport as identified by PK25199, and "Potential security exposure" issues as identified by (2) PK22747, (3) PK24334, (4) PK25740, and (5) PK26123.
nvd
CVE-2006-4223P4MEDIUMCVSS 5.0≤ 6.0.2.11v6.0.2+5 more2006-08-18
CVE-2006-4223 [MEDIUM] CVE-2006-4223: IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileServingEnabled to true or ExtendedDocumentRoot is used to place a JSP outside a WAR.file; (3) the First Failure Data Capture
nvd
CVE-2006-7166P4MEDIUMCVSS 5.0v5.0v5.0.1+32 more2007-03-20
CVE-2006-7166 [MEDIUM] CVE-2006-7166: IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP sou IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a specific JSP URL."
nvd
Ibm Websphere Application Server vulnerabilities | cvebase