Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 4 of 26
CVE-2026-8858P3HIGHCVSS 8.8v8.5v9.02026-06-22
CVE-2026-8858 [HIGH] CWE-94 CVE-2026-8858: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remo
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.
nvd
CVE-2020-4643P3HIGHCVSS 7.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-09-21
CVE-2020-4643 [HIGH] CWE-611 CVE-2020-4643: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Inje
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
nvd
CVE-2026-18499P3HIGHCVSS 8.1≥ 17.0.0.3, < 26.0.0.92026-08-12
CVE-2026-18499 [HIGH] CWE-285 CVE-2026-18499: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege es
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.
nvd
CVE-2026-11806P3HIGHCVSS 7.5≥ 17.0.0.3, < 26.0.0.72026-06-30
CVE-2026-11806 [HIGH] CWE-444 CVE-2026-11806: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary fil
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
nvd
CVE-2022-22476P3HIGHCVSS 8.8≥ 17.0.0.3, < 22.0.0.82022-07-08
CVE-2022-22476 [HIGH] CWE-290 CVE-2022-22476: IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable t
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.
nvd
CVE-2021-29754P3HIGHCVSS 8.8≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2021-06-11
CVE-2021-29754 [HIGH] CVE-2021-29754: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vuln
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
nvd
CVE-2024-37532P3HIGHCVSS 8.8v8.5.0.0v9.0.0.0+1 more2024-06-20
CVE-2024-37532 [HIGH] CWE-347 CVE-2024-37532: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.
nvd
CVE-2020-4276P3HIGHCVSS 7.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-03-26
CVE-2020-4276 [HIGH] CVE-2020-4276: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege esc
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.
nvd
CVE-2026-15328P3HIGHCVSS 8.1≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+3 more2026-07-28
CVE-2026-15328 [HIGH] CWE-444 CVE-2026-15328: IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTT
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling.
nvd
CVE-2024-35154P3HIGHCVSS 7.2≥ 8.5.0.0, ≤ 8.5.5.25≥ 9.0.0.0, ≤ 9.0.5.20+1 more2024-07-09
CVE-2024-35154 [HIGH] CWE-250 CVE-2024-35154: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has au
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.
nvd
CVE-2017-1151P3HIGHCVSS 8.1v8.0v8.5+2 more2017-03-20
CVE-2017-1151 [HIGH] CVE-2017-1151: IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured wit
IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could allow a user to gain elevated privileges on the system. IBM Reference #: 1999293.
nvd
CVE-2020-4534P3HIGHCVSS 8.8v7.0v8.0+2 more2020-08-03
CVE-2020-4534 [HIGH] CVE-2020-4534: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker t
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this vulnerability to execute arbitrary code with higher privileges. IBM X-Force ID: 182808.
nvd
CVE-2018-1840P3HIGHCVSS 8.1≥ 8.5.0.0, ≤ 8.5.5.14≥ 9.0.0.0, ≤ 9.0.0.9+2 more2018-12-03
CVE-2018-1840 [HIGH] CWE-668 CVE-2018-1840: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileg
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.
nvd
CVE-2009-0855P4MEDIUMCVSS 4.3PoCv6.1v6.1.0+23 more2009-03-09
CVE-2009-0855 [MEDIUM] CWE-79 CVE-2009-0855: Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2026-8620P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.282026-05-26
CVE-2026-8620 [HIGH] CWE-444 CVE-2026-8620: IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSpher
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.
nvd
CVE-2020-4449P3HIGHCVSS 7.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-06-05
CVE-2020-4449 [HIGH] CWE-502 CVE-2020-4449: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181230.
nvd
CVE-2026-14980P3HIGHCVSS 8.8≥ 17.0.0.3, < 26.0.0.92026-07-30
CVE-2026-14980 [HIGH] CWE-269 CVE-2026-14980: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site req
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.
nvd
CVE-2008-4283P3CRITICALCVSS 10.0≤ 5.1.1.19v5.0+43 more2009-02-10
CVE-2008-4283 [CRITICAL] CWE-20 CVE-2008-4283: CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS)
CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
nvd
CVE-2009-2088P3HIGHCVSS 7.5v6.1v6.1.0+29 more2009-08-13
CVE-2009-2088 [HIGH] CWE-287 CVE-2009-2088: The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.
The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass authentication via a request for a "secure URL," related to a certain invokefilterscompatibility property
nvd
CVE-2026-11595P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-30
CVE-2026-11595 [HIGH] CWE-22 CVE-2026-11595: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive info
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.
nvd