Ibm Websphere Application Server vulnerabilities
442 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
442
CISA KEV
1
actively exploited
Public exploits
12
Exploited in wild
2
Severity breakdown
CRITICAL49HIGH92MEDIUM261LOW40
Vulnerabilities
Page 4 of 23
CVE-2021-29842MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+7 more2021-09-16
CVE-2021-29842 [MEDIUM] CWE-307 CVE-2021-29842: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allo
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.
cvelistv5nvd
CVE-2021-29736HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-07-30
CVE-2021-29736 [HIGH] CVE-2021-29736: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated p
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.
cvelistv5nvd
CVE-2021-29754HIGHCVSS 8.8≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2021-06-11
CVE-2021-29754 [HIGH] CVE-2021-29754: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vuln
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
cvelistv5nvd
CVE-2021-20492HIGHCVSS 8.2≥ 8.0.0.0, ≤ 8.0.0.15≥ 8.5.0.0, ≤ 8.5.5.19+6 more2021-05-26
CVE-2021-20492 [HIGH] CWE-611 CVE-2021-20492: IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML Exter
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.
cvelistv5nvd
CVE-2021-20454HIGHCVSS 8.2≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-04-21
CVE-2021-20454 [HIGH] CWE-611 CVE-2021-20454: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injec
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.
cvelistv5nvd
CVE-2021-20453HIGHCVSS 8.2≥ 8.0.0.0, < 8.0.0.15≥ 8.5.0.0, < 8.5.5.20+4 more2021-04-20
CVE-2021-20453 [HIGH] CWE-611 CVE-2021-20453: IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648.
cvelistv5nvd
CVE-2021-20480MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+4 more2021-04-08
CVE-2021-20480 [MEDIUM] CWE-918 CVE-2021-20480: IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSR
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197502.
cvelistv5nvd
CVE-2020-5016MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-03-10
CVE-2020-5016 [MEDIUM] CWE-22 CVE-2020-5016: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse di
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. When application security is disabled and JAX-RPC applications are present, an attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary xml files on the system. This does not occ
cvelistv5nvd
CVE-2021-20354HIGHCVSS 7.5≥ 8.0.0.0, ≤ 8.0.0.15≥ 8.5.0.0, ≤ 8.5.5.19+4 more2021-02-18
CVE-2021-20354 [HIGH] CWE-22 CVE-2021-20354: IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directo
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
cvelistv5nvd
CVE-2021-20353HIGHCVSS 8.2≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2021-02-10
CVE-2021-20353 [HIGH] CWE-611 CVE-2021-20353: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Inje
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.
cvelistv5nvd
CVE-2020-4949HIGHCVSS 8.2≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-01-26
CVE-2020-4949 [HIGH] CWE-611 CVE-2020-4949: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Inje
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
cvelistv5nvd
CVE-2020-4782MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-10-28
CVE-2020-4782 [MEDIUM] CWE-22 CVE-2020-4782: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse di
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
cvelistv5nvd
CVE-2020-4576HIGHCVSS 7.5≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2020-10-01
CVE-2020-4576 [HIGH] CVE-2020-4576: IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to
IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 184428.
cvelistv5nvd
CVE-2020-4629LOWCVSS 3.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-09-30
CVE-2020-4629 [LOW] CWE-209 CVE-2020-4629: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized ac
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.
cvelistv5nvd
CVE-2020-4643HIGHCVSS 7.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-09-21
CVE-2020-4643 [HIGH] CWE-611 CVE-2020-4643: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Inje
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
cvelistv5nvd
CVE-2020-4590MEDIUMCVSS 6.5≥ 17.0.0.3, ≤ 20.0.0.92020-09-21
CVE-2020-4590 [MEDIUM] CVE-2020-4590: IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnec
IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.
nvd
CVE-2020-4578MEDIUMCVSS 5.4≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-09-10
CVE-2020-4578 [MEDIUM] CWE-79 CVE-2020-4578: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.
cvelistv5nvd
CVE-2020-4575MEDIUMCVSS 6.1≥ 8.5.0.0, < 8.5.5.18≥ 9.0.0.0, < 9.0.5.52020-08-27
CVE-2020-4575 [MEDIUM] CWE-79 CVE-2020-4575: IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 ar
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
nvd
CVE-2020-4589CRITICALCVSS 9.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-08-13
CVE-2020-4589 [CRITICAL] CWE-502 CVE-2020-4589: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arb
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.
cvelistv5nvd
CVE-2020-4534HIGHCVSS 8.8v7.0v8.0+2 more2020-08-03
CVE-2020-4534 [HIGH] CVE-2020-4534: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker t
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this vulnerability to execute arbitrary code with higher privileges. IBM X-Force ID: 182808.
cvelistv5nvd