cbcvebase.

Ibm Websphere Application Server vulnerabilities

517 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42

Vulnerabilities

Page 3 of 26
CVE-2026-10845P3HIGHCVSS 7.3≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-22
CVE-2026-10845 [HIGH] CWE-287 CVE-2026-10845: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
nvd
CVE-2020-4362P3HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-04-10
CVE-2020-4362 [HIGH] CVE-2020-4362: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege esc IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.
nvd
CVE-2021-20354P3HIGHCVSS 7.5≥ 8.0.0.0, ≤ 8.0.0.15≥ 8.5.0.0, ≤ 8.5.5.19+4 more2021-02-18
CVE-2021-20354 [HIGH] CWE-22 CVE-2021-20354: IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directo IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
nvd
CVE-2026-15325P3HIGHCVSS 8.7≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+3 more2026-07-28
CVE-2026-15325 [HIGH] CWE-444 CVE-2026-15325: IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTT IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
nvd
CVE-2016-5983P3HIGHCVSS 7.5v7.0v7.0.0.0+66 more2016-10-05
CVE-2016-5983 [HIGH] CWE-284 CVE-2016-5983: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11 IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.
nvd
CVE-2015-1885P3CRITICALCVSS 9.3v7.0v7.0.0.1+35 more2015-04-27
CVE-2015-1885 [CRITICAL] CWE-264 CVE-2015-1885: WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0 WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attackers to gain privileges via unspecified vectors.
nvd
CVE-2005-1112P4MEDIUMCVSS 5.0PoCv5.0v5.0.1+18 more2005-05-02
CVE-2005-1112 [MEDIUM] CVE-2005-1112: IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.
nvd
CVE-2026-10842P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+3 more2026-07-30
CVE-2026-10842 [HIGH] CWE-289 CVE-2026-10842: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0. IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.
nvd
CVE-2025-14917P3CRITICALCVSS 9.8≥ 17.0.0.3, < 26.0.0.42026-03-25
CVE-2025-14917 [CRITICAL] CWE-1393 CVE-2025-14917: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Serve IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.
nvd
CVE-2021-20454P3HIGHCVSS 8.2≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-04-21
CVE-2021-20454 [HIGH] CWE-611 CVE-2021-20454: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injec IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.
nvd
CVE-2021-29736P3HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-07-30
CVE-2021-29736 [HIGH] CVE-2021-29736: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated p IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.
nvd
CVE-2021-20453P3HIGHCVSS 8.2≥ 8.0.0.0, < 8.0.0.15≥ 8.5.0.0, < 8.5.5.20+4 more2021-04-20
CVE-2021-20453 [HIGH] CWE-611 CVE-2021-20453: IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648.
nvd
CVE-2021-20492P3HIGHCVSS 8.2≥ 8.0.0.0, ≤ 8.0.0.15≥ 8.5.0.0, ≤ 8.5.5.19+6 more2021-05-26
CVE-2021-20492 [HIGH] CWE-611 CVE-2021-20492: IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML Exter IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.
nvd
CVE-2026-15064P3HIGHCVSS 8.7≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+3 more2026-07-28
CVE-2026-15064 [HIGH] CWE-444 CVE-2026-15064: IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTT IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
nvd
CVE-2015-5041P3CRITICALCVSS 9.1≤ 3.0.9.202016-06-06
CVE-2015-5041 [CRITICAL] CWE-200 CVE-2015-5041: The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.
nvd
CVE-2026-15280P3HIGHCVSS 7.5≥ 17.0.0.3, < 26.0.0.92026-07-28
CVE-2026-15280 [HIGH] CWE-22 CVE-2026-15280: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is aff IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.
nvd
CVE-2025-14923P3CRITICALCVSS 9.8≥ 17.0.0.3, < 26.0.0.32026-03-03
CVE-2025-14923 [CRITICAL] CWE-321 CVE-2025-14923: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Serve IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
nvd
CVE-2023-27554P3CRITICALCVSS 9.1≥ 8.5.0.0, < 8.5.5.24≥ 9.0.0.0, < 9.0.5.16+1 more2023-05-11
CVE-2023-27554 [CRITICAL] CWE-611 CVE-2023-27554: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249185.
nvd
CVE-2018-1901P3HIGHCVSS 8.8≥ 8.5.0.0, ≤ 8.5.5.14≥ 9.0.0.0, ≤ 9.0.0.9+3 more2018-12-12
CVE-2018-1901 [HIGH] CVE-2018-1901: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain eleva IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.
nvd
CVE-2026-8644P3CRITICALCVSS 9.1≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-01
CVE-2026-8644 [CRITICAL] CWE-290 CVE-2026-8644: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase