Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 23 of 26
CVE-2008-4285P4MEDIUMCVSS 5.0v6.1v6.1.0+10 more2009-02-17
CVE-2008-4285 [MEDIUM] CWE-399 CVE-2008-4285: Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet
Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19, when a component statistic is enabled, allows attackers to cause a denial of service (daemon crash) via vectors related to "a gradual degradation in performan
nvd
CVE-2011-1317P4MEDIUMCVSS 5.0v6.1.0v6.1.0.0+31 more2011-03-08
CVE-2011-1317 [MEDIUM] CWE-399 CVE-2011-1317: Memory leak in com.ibm.ws.jsp.runtime.WASJSPStrBufferImpl in the JavaServer Pages (JSP) component in
Memory leak in com.ibm.ws.jsp.runtime.WASJSPStrBufferImpl in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by sending many JSP requests that trigger large responses.
nvd
CVE-2011-1315P4MEDIUMCVSS 5.0≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1315 [MEDIUM] CWE-399 CVE-2011-1315: Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows
Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via network connections associated with a NULL return value from a synchronous JMS receive call.
nvd
CVE-2010-2323P4MEDIUMCVSS 5.0≤ 7.0.0.10v7.0+9 more2010-06-18
CVE-2010-2323 [MEDIUM] CWE-200 CVE-2010-2323: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain s
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_create.log file that is associated with profile creation by the BBOWWPFx job and the zPMT.
nvd
CVE-2007-3265P4MEDIUMCVSS 4.3≤ 6.1.0.72007-06-19
CVE-2007-3265 [MEDIUM] CVE-2007-3265: Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Serve
Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-4220P4MEDIUMCVSS 4.3v7.0v7.0.0.1+11 more2010-11-09
CVE-2010-4220 [MEDIUM] CWE-79 CVE-2010-4220: Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Co
Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Console component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."
nvd
CVE-2005-2091P4MEDIUMCVSS 4.3v5.0v5.1.02005-07-05
CVE-2005-2091 [MEDIUM] CVE-2005-2091: IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web appl
IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the recei
nvd
CVE-2010-0784P4MEDIUMCVSS 4.3v7.0v7.0.0.1+11 more2010-11-09
CVE-2010-0784 [MEDIUM] CWE-79 CVE-2010-0784: Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2009-0856P4MEDIUMCVSS 4.3v6.1v6.1.0.0+22 more2009-03-09
CVE-2009-0856 [MEDIUM] CWE-79 CVE-2009-0856: Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Applicat
Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, and 6.1 before 6.1.0.23 on z/OS, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-0779P4MEDIUMCVSS 4.3v6.1v6.1.0+52 more2010-06-24
CVE-2010-0779 [MEDIUM] CWE-79 CVE-2010-0779: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-0778P4MEDIUMCVSS 4.3v6.1v6.1.0+24 more2010-06-24
CVE-2010-0778 [MEDIUM] CWE-79 CVE-2010-0778: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-0707P4MEDIUMCVSS 4.3v7.22012-02-23
CVE-2012-0707 [MEDIUM] CWE-79 CVE-2012-0707: Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attacke
Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attackers to inject arbitrary web script or HTML via crafted text input to a coach that is configured with a document attachment control section.
nvd
CVE-2026-11537P4MEDIUMCVSS 4.3v9.0v8.52026-09-18
CVE-2026-11537 [MEDIUM] CWE-650 CVE-2026-11537: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive info
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
nvd
CVE-2007-1944P4MEDIUMCVSS 5.0≤ 6.1.0.12007-04-11
CVE-2007-1944 [MEDIUM] CWE-119 CVE-2007-1944: The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attac
The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.
nvd
CVE-2011-1318P4MEDIUMCVSS 5.0≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1318 [MEDIUM] CWE-399 CVE-2011-1318: Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) compon
Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) by accessing a JSP page of an application that is repeatedly stopped and restarted.
nvd
CVE-2006-7164P4MEDIUMCVSS 4.3v5.0.1v5.0.2+16 more2007-03-20
CVE-2006-7164 [MEDIUM] CVE-2006-7164: SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does n
SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.
nvd
CVE-2007-5798P4MEDIUMCVSS 4.3≤ 6.1.0.122007-11-03
CVE-2007-5798 [MEDIUM] CWE-79 CVE-2007-5798: Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user cons
Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to inject arbitrary web script or HTML via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
nvd
CVE-2008-7274P4MEDIUMCVSS 4.3v6.1.0.92011-02-15
CVE-2008-7274 [MEDIUM] CWE-20 CVE-2008-7274: IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows
IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2) providing an empty password.
nvd
CVE-2011-1209P4MEDIUMCVSS 4.3v6.1.0v6.1.0.0+44 more2011-05-04
CVE-2011-1209 [MEDIUM] CWE-310 CVE-2011-1209: IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Se
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Security XML encryption algorithm, which makes it easier for remote attackers to obtain plaintext data from a (1) JAX-RPC or (2) JAX-WS Web Services request via unspecified vectors related to a "decryption attack."
nvd
CVE-2011-1312P4MEDIUMCVSS 4.0v6.1.0v6.1.0.0+28 more2011-03-08
CVE-2011-1312 [MEDIUM] CWE-264 CVE-2011-1312: The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.
The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.31 and 7.x before 7.0.0.15 does not prevent modifications of the primary admin id, which allows remote authenticated administrators to bypass intended access restrictions by mapping a (1) user or (2) group to an administrator role.
nvd