Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 22 of 26
CVE-2006-3231P4MEDIUMCVSS 4.3v2.0v3.0+48 more2006-06-27
CVE-2006-3231 [MEDIUM] CVE-2006-3231: Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServin
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."
nvd
CVE-2014-3022P4MEDIUMCVSS 4.3v8.0.0.0v8.0.0.1+35 more2014-08-22
CVE-2014-3022 [MEDIUM] CWE-200 CVE-2014-3022: IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition.
nvd
CVE-2011-0315P4MEDIUMCVSS 4.3v6.1v6.1.0+32 more2011-01-12
CVE-2011-0315 [MEDIUM] CWE-79 CVE-2011-0315: Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebS
Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to the lack of an error page for an application.
nvd
CVE-2014-0896P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+3 more2014-05-01
CVE-2014-0896 [MEDIUM] CWE-200 CVE-2014-0896: IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers
IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information via a crafted request.
nvd
CVE-2011-1362P4MEDIUMCVSS 4.3v6.1v6.1.0+43 more2012-01-15
CVE-2011-1362 [MEDIUM] CVE-2011-1362: Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for C
nvd
CVE-2009-2748P4MEDIUMCVSS 4.3v6.1.0v6.1.0.0+21 more2011-10-30
CVE-2009-2748 [MEDIUM] CWE-79 CVE-2009-2748: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-0768P4MEDIUMCVSS 4.3≤ 6.0.2.39v6.0.2+41 more2010-04-01
CVE-2010-0768 [MEDIUM] CWE-79 CVE-2010-0768: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the URI.
nvd
CVE-2009-2742P4MEDIUMCVSS 4.3v6.1v6.1.0.1+13 more2009-09-21
CVE-2009-2742 [MEDIUM] CWE-79 CVE-2009-2742: Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6
Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input.
nvd
CVE-2009-0899P4MEDIUMCVSS 4.3≥ 6.1, ≤ 6.1.0.24≥ 7.0, ≤ 7.0.0.42009-06-03
CVE-2009-0899 [MEDIUM] CWE-264 CVE-2009-0899: IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere P
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which a
nvd
CVE-2024-45073P4MEDIUMCVSS 4.8v8.5v9.0+1 more2024-09-30
CVE-2024-45073 [MEDIUM] CWE-79 CVE-2024-45073: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vuln
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-45071P4MEDIUMCVSS 4.8≥ 8.5.0.0, ≤ 8.5.5.26≥ 9.0.0.0, ≤ 9.0.5.21+1 more2024-10-16
CVE-2024-45071 [MEDIUM] CWE-79 CVE-2024-45071: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vuln
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2014-0857P4MEDIUMCVSS 4.0v8.5.0.0v8.5.0.1+13 more2014-05-01
CVE-2014-0857 [MEDIUM] CWE-200 CVE-2014-0857: The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x be
The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.
nvd
CVE-2015-0174P4MEDIUMCVSS 4.0v8.5.0.0v8.5.0.1+6 more2015-04-27
CVE-2015-0174 [MEDIUM] CWE-200 CVE-2015-0174: The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not proper
The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-4758P4MEDIUMCVSS 4.0v7.2v7.2.0.1+4 more2014-09-04
CVE-2014-4758 [MEDIUM] CWE-264 CVE-2014-4758: IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow re
IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.
nvd
CVE-2013-5414P4LOWCVSS 3.5v7.0v7.0.0.1+37 more2013-11-18
CVE-2013-5414 [LOW] CWE-264 CVE-2013-5414: The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 befor
The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a m
nvd
CVE-2006-2434P4MEDIUMCVSS 5.0v5.1.12006-05-17
CVE-2006-2434 [MEDIUM] CVE-2006-2434: Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mo
Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace.
nvd
CVE-2007-4833P4MEDIUMCVSS 5.0≤ 6.1.0.92007-09-12
CVE-2007-4833 [MEDIUM] CVE-2007-4833: Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before
Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK44789.
nvd
CVE-2006-4222P4MEDIUMCVSS 5.0≤ 6.0.2.11v6.0.2+5 more2006-08-18
CVE-2006-4222 [MEDIUM] CVE-2006-4222: Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspec
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspecified vectors and impact, including (1) an "authority problem" in ThreadIdentitySupport as identified by PK25199, and "Potential security exposure" issues as identified by (2) PK22747, (3) PK24334, (4) PK25740, and (5) PK26123.
nvd
CVE-2006-4223P4MEDIUMCVSS 5.0≤ 6.0.2.11v6.0.2+5 more2006-08-18
CVE-2006-4223 [MEDIUM] CVE-2006-4223: IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain
IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileServingEnabled to true or ExtendedDocumentRoot is used to place a JSP outside a WAR.file; (3) the First Failure Data Capture
nvd
CVE-2006-7166P4MEDIUMCVSS 5.0v5.0v5.0.1+32 more2007-03-20
CVE-2006-7166 [MEDIUM] CVE-2006-7166: IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP sou
IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a specific JSP URL."
nvd