Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 24 of 26
CVE-2009-0506P4MEDIUMCVSS 6.2v5.1.0v6.0.2+11 more2009-02-25
CVE-2009-0506 [MEDIUM] CVE-2009-0506: Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) mul
nvd
CVE-2006-4137P4MEDIUMCVSS 5.0v6.0v6.0.0.1+14 more2006-08-14
CVE-2006-4137 [MEDIUM] CVE-2006-4137: IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via
IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.
nvd
CVE-2013-4006P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+2 more2013-11-18
CVE-2013-4006 [MEDIUM] CWE-310 CVE-2013-4006: IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.
nvd
CVE-2005-4413P4MEDIUMCVSS 4.3v6.02005-12-20
CVE-2005-4413 [MEDIUM] CVE-2005-4413: Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application S
Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application Server 6 allow remote attackers to inject arbitrary web script or HTML via the (1) E-mail address field to (a) PlantsByWebSphere/login.jsp, (2) message field to (b) TechnologySample/BulletinBoard Script, (3) Email address field to (c) TechnologySamples/Subscript
nvd
CVE-2011-1308P4MEDIUMCVSS 4.3≤ 7.0.0.13v2.0+137 more2011-03-08
CVE-2011-1308 [MEDIUM] CWE-79 CVE-2011-1308: Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2011-1319P4MEDIUMCVSS 4.0v6.1.0v6.1.0.0+30 more2011-03-08
CVE-2011-1319 [MEDIUM] CWE-399 CVE-2011-1319: The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x bef
The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote authenticated users to cause a denial of service (memory consumption) by using a Lightweight Third-Party Authentication (LTPA) token for authentication.
nvd
CVE-2007-5799P4MEDIUMCVSS 4.3≤ 6.1.0.122007-11-03
CVE-2007-5799 [MEDIUM] CWE-352 CVE-2007-5799: Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI us
Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
nvd
CVE-2015-5004P4MEDIUMCVSS 4.0v8.0.0.0v8.0.0.1+21 more2015-12-15
CVE-2015-5004 [MEDIUM] CWE-200 CVE-2015-5004: The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8
The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-4770P4LOWCVSS 3.5v6.0v6.0.0.1+118 more2014-09-23
CVE-2014-4770 [LOW] CWE-79 CVE-2014-4770: Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-6323P4LOWCVSS 3.5v7.0v7.0.0.1+40 more2014-05-01
CVE-2013-6323 [LOW] CWE-79 CVE-2013-6323: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-6725P4LOWCVSS 3.5v6.1v7.0+39 more2014-01-16
CVE-2013-6725 [LOW] CWE-79 CVE-2013-6725: Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2026-11545P4LOWCVSS 3.7v8.5v9.02026-09-18
CVE-2026-11545 [LOW] CWE-862 CVE-2026-11545: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive infor
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.
nvd
CVE-2006-1619P4MEDIUMCVSS 5.0v4.0.1v4.0.2+1 more2006-04-05
CVE-2006-1619 [MEDIUM] CVE-2006-1619: IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of se
IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a large header.
nvd
CVE-1999-0852P4HIGHCVSS 7.2v3.01999-12-02
CVE-1999-0852 [HIGH] CVE-1999-0852: IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data
IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.
nvd
CVE-2005-4833P4MEDIUMCVSS 4.3v6.02005-12-31
CVE-2005-4833 [MEDIUM] CVE-2005-4833: IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR
IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to lack of normalization of the URL format.
nvd
CVE-2006-7165P4MEDIUMCVSS 4.3v5.1.0v5.1.0.2+4 more2007-03-20
CVE-2006-7165 [MEDIUM] CVE-2006-7165: IBM WebSphere Application Server (WAS) 5.0 through 5.1.1.0 allows remote attackers to obtain JSP sou
IBM WebSphere Application Server (WAS) 5.0 through 5.1.1.0 allows remote attackers to obtain JSP source code and other sensitive information via certain "special URIs."
nvd
CVE-2010-2326P4MEDIUMCVSS 4.3v7.0v7.0.0.1+4 more2010-06-18
CVE-2010-2326 [MEDIUM] CWE-200 CVE-2010-2326: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11, when addNode -trace is used during node
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11, when addNode -trace is used during node federation, allows attackers to obtain sensitive information about CIMMetadataCollectorImpl trace actions by reading the addNode.log file.
nvd
CVE-2010-0770P4MEDIUMCVSS 4.0≤ 6.0.2.39v6.0+46 more2010-04-01
CVE-2010-0770 [MEDIUM] CWE-399 CVE-2010-0770: IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.
IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of service (ORB ListenerThread hang) by aborting an SSL handshake.
nvd
CVE-2010-0781P4MEDIUMCVSS 4.0v6.1.0v6.1.0.1+16 more2010-09-21
CVE-2010-0781 [MEDIUM] CVE-2010-0781: Unspecified vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.
Unspecified vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted URL.
nvd
CVE-2015-1946P4MEDIUMCVSS 4.4v7.0v8.0.0.0+9 more2015-07-14
CVE-2015-1946 [MEDIUM] CWE-264 CVE-2015-1946: IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 befo
IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.
nvd