cbcvebase.

Ibm Websphere Application Server vulnerabilities

451 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
451
CISA KEV
1
actively exploited
Public exploits
13
Exploited in wild
2
Severity breakdown
CRITICAL53HIGH95MEDIUM263LOW40

Vulnerabilities

Page 23 of 23
CVE-2002-1153MEDIUMCVSS 5.0v4.0.32002-10-11
CVE-2002-1153 [MEDIUM] CVE-2002-1153: IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execut IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".
nvd
CVE-2001-1189MEDIUMCVSS 4.6v3.0v3.0.2+8 more2001-12-13
CVE-2001-1189 [MEDIUM] CVE-2001-1189: IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server. IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
nvd
CVE-2001-0824HIGHCVSS 7.5v3.0.2v3.52001-12-06
CVE-2001-0824 [HIGH] CVE-2001-0824: Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to exec Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
nvd
CVE-2001-0962HIGHCVSS 7.5≤ 3.5.32001-09-19
CVE-2001-0962 [HIGH] CVE-2001-0962: IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which a IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
nvd
CVE-2001-0390MEDIUMCVSS 5.0PoCv5.1.0.32001-07-02
CVE-2001-0390 [MEDIUM] CVE-2001-0390: IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly ca IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
nvd
CVE-2001-0389MEDIUMCVSS 5.0v5.1.0.32001-07-02
CVE-2001-0389 [MEDIUM] CVE-2001-0389: IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
nvd
CVE-2001-0122MEDIUMCVSS 5.0PoCv3.522001-03-13
CVE-2001-0122 [MEDIUM] CVE-2001-0122: Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
nvd
CVE-2000-0848CRITICALCVSS 10.0PoCv3.0.22000-11-14
CVE-2000-0848 [CRITICAL] CVE-2000-0848: Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arb Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
nvd
CVE-2000-0652MEDIUMCVSS 5.0PoCv2.0v3.0+1 more2000-07-24
CVE-2000-0652 [MEDIUM] CVE-2000-0652: IBM WebSphere allows remote attackers to read source code for executable web files by directly calli IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.
nvd
CVE-2000-0497HIGHCVSS 7.5v3.0.22000-06-08
CVE-2000-0497 [HIGH] CWE-178 CVE-2000-0497: IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesti IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
nvd
CVE-1999-0852HIGHCVSS 7.2v3.01999-12-02
CVE-1999-0852 [HIGH] CVE-1999-0852: IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase