cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 3 of 24
CVE-2021-20492P3HIGHCVSS 8.2≥ 8.0.0.0, ≤ 8.0.0.15≥ 8.5.0.0, ≤ 8.5.5.19+6 more2021-05-26
CVE-2021-20492 [HIGH] CWE-611 CVE-2021-20492: IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML Exter IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.
nvd
CVE-2015-1885P3CRITICALCVSS 9.3v7.0v7.0.0.1+35 more2015-04-27
CVE-2015-1885 [CRITICAL] CWE-264 CVE-2015-1885: WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0 WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attackers to gain privileges via unspecified vectors.
nvd
CVE-2015-5041P3CRITICALCVSS 9.1≤ 3.0.9.202016-06-06
CVE-2015-5041 [CRITICAL] CWE-200 CVE-2015-5041: The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.
nvd
CVE-2025-14923P3CRITICALCVSS 9.8≥ 17.0.0.3, < 26.0.0.32026-03-03
CVE-2025-14923 [CRITICAL] CWE-321 CVE-2025-14923: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Serve IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
nvd
CVE-2023-27554P3CRITICALCVSS 9.1≥ 8.5.0.0, < 8.5.5.24≥ 9.0.0.0, < 9.0.5.16+1 more2023-05-11
CVE-2023-27554 [CRITICAL] CWE-611 CVE-2023-27554: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249185.
nvd
CVE-2018-1901P3HIGHCVSS 8.8≥ 8.5.0.0, ≤ 8.5.5.14≥ 9.0.0.0, ≤ 9.0.0.9+3 more2018-12-12
CVE-2018-1901 [HIGH] CVE-2018-1901: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain eleva IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.
nvd
CVE-2026-8858P3HIGHCVSS 8.8v8.5v9.02026-06-22
CVE-2026-8858 [HIGH] CWE-94 CVE-2026-8858: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remo IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.
nvd
CVE-2020-4643P3HIGHCVSS 7.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-09-21
CVE-2020-4643 [HIGH] CWE-611 CVE-2020-4643: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Inje IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
nvd
CVE-2026-8644P3CRITICALCVSS 9.1≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-01
CVE-2026-8644 [CRITICAL] CWE-290 CVE-2026-8644: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
nvd
CVE-2022-22476P3HIGHCVSS 8.8≥ 17.0.0.3, < 22.0.0.82022-07-08
CVE-2022-22476 [HIGH] CWE-290 CVE-2022-22476: IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable t IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.
nvd
CVE-2021-29754P3HIGHCVSS 8.8≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2021-06-11
CVE-2021-29754 [HIGH] CVE-2021-29754: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vuln IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
nvd
CVE-2024-37532P3HIGHCVSS 8.8v8.5.0.0v9.0.0.0+1 more2024-06-20
CVE-2024-37532 [HIGH] CWE-347 CVE-2024-37532: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.
nvd
CVE-2020-4276P3HIGHCVSS 7.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-03-26
CVE-2020-4276 [HIGH] CVE-2020-4276: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege esc IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.
nvd
CVE-2024-35154P3HIGHCVSS 7.2≥ 8.5.0.0, ≤ 8.5.5.25≥ 9.0.0.0, ≤ 9.0.5.20+1 more2024-07-09
CVE-2024-35154 [HIGH] CWE-250 CVE-2024-35154: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has au IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.
nvd
CVE-2026-11806P3HIGHCVSS 7.5≥ 17.0.0.3, < 26.0.0.72026-06-30
CVE-2026-11806 [HIGH] CWE-444 CVE-2026-11806: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary fil IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
nvd
CVE-2020-4449P3HIGHCVSS 7.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-06-05
CVE-2020-4449 [HIGH] CWE-502 CVE-2020-4449: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181230.
nvd
CVE-2017-1151P3HIGHCVSS 8.1v8.0v8.5+2 more2017-03-20
CVE-2017-1151 [HIGH] CVE-2017-1151: IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured wit IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could allow a user to gain elevated privileges on the system. IBM Reference #: 1999293.
nvd
CVE-2020-4534P3HIGHCVSS 8.8v7.0v8.0+2 more2020-08-03
CVE-2020-4534 [HIGH] CVE-2020-4534: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker t IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this vulnerability to execute arbitrary code with higher privileges. IBM X-Force ID: 182808.
nvd
CVE-2018-1840P3HIGHCVSS 8.1≥ 8.5.0.0, ≤ 8.5.5.14≥ 9.0.0.0, ≤ 9.0.0.9+2 more2018-12-03
CVE-2018-1840 [HIGH] CWE-668 CVE-2018-1840: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileg IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.
nvd
CVE-2008-4283P3CRITICALCVSS 10.0≤ 5.1.1.19v5.0+43 more2009-02-10
CVE-2008-4283 [CRITICAL] CWE-20 CVE-2008-4283: CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase