cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 4 of 24
CVE-2009-0855P4MEDIUMCVSS 4.3PoCv6.1v6.1.0+23 more2009-03-09
CVE-2009-0855 [MEDIUM] CWE-79 CVE-2009-0855: Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2024-56339P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 25.0.0.7v9.0.0.0+1 more2025-08-07
CVE-2024-56339 [HIGH] CWE-650 CVE-2024-56339: IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0. IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.
nvd
CVE-2026-8620P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.282026-05-26
CVE-2026-8620 [HIGH] CWE-444 CVE-2026-8620: IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSpher IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.
nvd
CVE-2009-2088P3HIGHCVSS 7.5v6.1v6.1.0+29 more2009-08-13
CVE-2009-2088 [HIGH] CWE-287 CVE-2009-2088: The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1. The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass authentication via a request for a "secure URL," related to a certain invokefilterscompatibility property
nvd
CVE-2026-11595P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-30
CVE-2026-11595 [HIGH] CWE-22 CVE-2026-11595: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive info IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.
nvd
CVE-2000-0652P4MEDIUMCVSS 5.0PoCv2.0v3.0+1 more2000-07-24
CVE-2000-0652 [MEDIUM] CVE-2000-0652: IBM WebSphere allows remote attackers to read source code for executable web files by directly calli IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.
nvd
CVE-2017-1137P3HIGHCVSS 8.1v8.0v8.5+1 more2017-05-10
CVE-2017-1137 [HIGH] CVE-2017-1137: IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549.
nvd
CVE-2019-4269P3HIGHCVSS 7.5≥ 9.0.0.0, ≤ 9.0.0.11v7.0+4 more2019-06-28
CVE-2019-4269 [HIGH] CWE-209 CVE-2019-4269: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console could allow a remote attacker IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console could allow a remote attacker to obtain sensitive information when a specially crafted url causes a stack trace to be dumped. IBM X-Force ID: 160202.
nvd
CVE-2006-2342P3HIGHCVSS 7.5v6.0.22006-05-12
CVE-2006-2342 [HIGH] CVE-2006-2342: IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentica IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root.
nvd
CVE-2025-36124P3HIGHCVSS 7.5≥ 17.0.0.3, < 25.0.0.92025-08-12
CVE-2025-36124 [HIGH] CWE-268 CVE-2025-36124: IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration
nvd
CVE-2026-11708P3CRITICALCVSS 9.3≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-30
CVE-2026-11708 [CRITICAL] CWE-79 CVE-2026-11708: IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
nvd
CVE-2026-11712P3CRITICALCVSS 9.3≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-30
CVE-2026-11712 [CRITICAL] CWE-79 CVE-2026-11712: IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
nvd
CVE-2005-3498P4MEDIUMCVSS 4.3PoC≥ 5.0.0, < 5.02.15≥ 5.1.0, < 5.1.1.8+1 more2005-11-04
CVE-2005-3498 [MEDIUM] CWE-200 CVE-2005-3498: IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain sensitive information.
nvd
CVE-2020-4576P3HIGHCVSS 7.5≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2020-10-01
CVE-2020-4576 [HIGH] CVE-2020-4576: IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 184428.
nvd
CVE-2016-2945P3HIGHCVSS 7.5v8.5.5.8v8.5.5.92016-07-08
CVE-2016-2945 [HIGH] CWE-264 CVE-2016-2945: The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 L The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote authenticated users to gain privileges via an external reference in a Swagger document.
nvd
CVE-2026-9071P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+3 more2026-06-22
CVE-2026-9071 [HIGH] CWE-400 CVE-2026-9071: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0. IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2026-4410P3HIGHCVSS 7.5≥ 8.5.0.0, ≤ 8.5.5.29≥ 9.0.0.0, ≤ 9.0.5.27+3 more2026-05-27
CVE-2026-4410 [HIGH] CWE-400 CVE-2026-4410: IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application S IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2023-50314P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 24.0.0.82024-08-14
CVE-2023-50314 [HIGH] CWE-295 CVE-2023-50314: IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with acce IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274713.
nvd
CVE-2020-4782P3MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-10-28
CVE-2020-4782 [MEDIUM] CWE-22 CVE-2020-4782: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse di IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
nvd
CVE-2025-14915P3HIGHCVSS 7.2≥ 17.0.0.3, < 26.0.0.42026-03-25
CVE-2025-14915 [HIGH] CWE-200 CVE-2025-14915: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Serve IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase