Ibm Websphere Application Server vulnerabilities
451 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
451
CISA KEV
1
actively exploited
Public exploits
13
Exploited in wild
2
Severity breakdown
CRITICAL53HIGH95MEDIUM263LOW40
Vulnerabilities
Page 4 of 23
CVE-2022-22477MEDIUMCVSS 6.1v8.5v9.02022-07-14
CVE-2022-22477 [MEDIUM] CWE-79 CVE-2022-22477: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605.
nvd
CVE-2022-22476HIGHCVSS 8.8≥ 17.0.0.3, < 22.0.0.82022-07-08
CVE-2022-22476 [HIGH] CWE-290 CVE-2022-22476: IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable t
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.
nvd
CVE-2022-22365MEDIUMCVSS 5.9≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2022-05-20
CVE-2022-22365 [MEDIUM] CVE-2022-22365: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxPr
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, is vulnerable to spoofing by allowing a man-in-the-middle attacker to spoof SSL server hostnames. IBM X-Force ID: 220904.
nvd
CVE-2022-22475MEDIUMCVSS 6.5≥ 17.0.0.3, ≤ 22.0.0.52022-05-17
CVE-2022-22475 [MEDIUM] CVE-2022-22475: IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable t
IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM X-Force ID: 225603.
nvd
CVE-2022-22393MEDIUMCVSS 6.5≥ 17.0.0.3, ≤ 22.0.0.52022-05-13
CVE-2022-22393 [MEDIUM] CVE-2022-22393: IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 featur
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could allow an authenticated user to issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server. IBM X-Force ID: 222078.
nvd
CVE-2021-39038MEDIUMCVSS 5.4≥ 9.0.0.0, < 9.0.5.12≥ 17.0.0.3, ≤ 22.0.0.2+1 more2022-02-24
CVE-2021-39038 [MEDIUM] CWE-1021 CVE-2021-39038: IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 2
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch furth
nvd
CVE-2021-39031HIGHCVSS 8.8≥ 17.0.0.3, ≤ 22.0.0.12022-01-25
CVE-2021-39031 [HIGH] CWE-74 CVE-2021-39031: IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authentica
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.
nvd
CVE-2022-22310MEDIUMCVSS 6.5≥ 21.0.0.10, ≤ 21.0.0.122022-01-19
CVE-2022-22310 [MEDIUM] CVE-2022-22310: IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expec
IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 217224.
nvd
CVE-2021-38951HIGHCVSS 7.5v7.0v8.0+2 more2021-12-09
CVE-2021-38951 [HIGH] CVE-2021-38951: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405.
nvd
CVE-2021-29842MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+7 more2021-09-16
CVE-2021-29842 [MEDIUM] CWE-307 CVE-2021-29842: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allo
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.
nvd
CVE-2021-29736HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-07-30
CVE-2021-29736 [HIGH] CVE-2021-29736: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated p
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.
nvd
CVE-2021-29754HIGHCVSS 8.8≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2021-06-11
CVE-2021-29754 [HIGH] CVE-2021-29754: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vuln
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
nvd
CVE-2021-20492HIGHCVSS 8.2≥ 8.0.0.0, ≤ 8.0.0.15≥ 8.5.0.0, ≤ 8.5.5.19+6 more2021-05-26
CVE-2021-20492 [HIGH] CWE-611 CVE-2021-20492: IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML Exter
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.
nvd
CVE-2021-20454HIGHCVSS 8.2≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-04-21
CVE-2021-20454 [HIGH] CWE-611 CVE-2021-20454: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injec
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.
nvd
CVE-2021-20453HIGHCVSS 8.2≥ 8.0.0.0, < 8.0.0.15≥ 8.5.0.0, < 8.5.5.20+4 more2021-04-20
CVE-2021-20453 [HIGH] CWE-611 CVE-2021-20453: IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648.
nvd
CVE-2021-20480MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+4 more2021-04-08
CVE-2021-20480 [MEDIUM] CWE-918 CVE-2021-20480: IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSR
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197502.
nvd
CVE-2020-5016MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-03-10
CVE-2020-5016 [MEDIUM] CWE-22 CVE-2020-5016: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse di
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. When application security is disabled and JAX-RPC applications are present, an attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary xml files on the system. This does not occ
nvd
CVE-2021-20354HIGHCVSS 7.5≥ 8.0.0.0, ≤ 8.0.0.15≥ 8.5.0.0, ≤ 8.5.5.19+4 more2021-02-18
CVE-2021-20354 [HIGH] CWE-22 CVE-2021-20354: IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directo
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
nvd
CVE-2021-20353HIGHCVSS 8.2≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2021-02-10
CVE-2021-20353 [HIGH] CWE-611 CVE-2021-20353: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Inje
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.
nvd
CVE-2020-4949HIGHCVSS 8.2≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-01-26
CVE-2020-4949 [HIGH] CWE-611 CVE-2020-4949: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Inje
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
nvd