cbcvebase.

Ibm Websphere Application Server vulnerabilities

517 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42

Vulnerabilities

Page 5 of 26
CVE-2000-0652P4MEDIUMCVSS 5.0PoCv2.0v3.0+1 more2000-07-24
CVE-2000-0652 [MEDIUM] CVE-2000-0652: IBM WebSphere allows remote attackers to read source code for executable web files by directly calli IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.
nvd
CVE-2024-56339P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 25.0.0.7v9.0.0.0+1 more2025-08-07
CVE-2024-56339 [HIGH] CWE-650 CVE-2024-56339: IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0. IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.
nvd
CVE-2026-2482P3HIGHCVSS 8.8≥ 17.0.0.3, < 26.0.0.92026-07-29
CVE-2026-2482 [HIGH] CWE-352 CVE-2026-2482: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site req IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2017-1137P3HIGHCVSS 8.1v8.0v8.5+1 more2017-05-10
CVE-2017-1137 [HIGH] CVE-2017-1137: IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549.
nvd
CVE-2019-4269P3HIGHCVSS 7.5≥ 9.0.0.0, ≤ 9.0.0.11v7.0+4 more2019-06-28
CVE-2019-4269 [HIGH] CWE-209 CVE-2019-4269: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console could allow a remote attacker IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console could allow a remote attacker to obtain sensitive information when a specially crafted url causes a stack trace to be dumped. IBM X-Force ID: 160202.
nvd
CVE-2026-9327P3HIGHCVSS 8.1≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-09-10
CVE-2026-9327 [HIGH] CWE-269 CVE-2026-9327: IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
nvd
CVE-2026-9336P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-09-10
CVE-2026-9336 [HIGH] CWE-306 CVE-2026-9336: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sendin IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.
nvd
CVE-2025-14915P3HIGHCVSS 7.2≥ 17.0.0.3, < 26.0.0.42026-03-25
CVE-2025-14915 [HIGH] CWE-200 CVE-2025-14915: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Serve IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.
nvd
CVE-2026-11712P3CRITICALCVSS 9.3≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-30
CVE-2026-11712 [CRITICAL] CWE-79 CVE-2026-11712: IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
nvd
CVE-2026-11708P3CRITICALCVSS 9.3≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-06-30
CVE-2026-11708 [CRITICAL] CWE-79 CVE-2026-11708: IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
nvd
CVE-2006-2342P3HIGHCVSS 7.5v6.0.22006-05-12
CVE-2006-2342 [HIGH] CVE-2006-2342: IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentica IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root.
nvd
CVE-2005-3498P4MEDIUMCVSS 4.3PoC≥ 5.0.0, < 5.02.15≥ 5.1.0, < 5.1.1.8+1 more2005-11-04
CVE-2005-3498 [MEDIUM] CWE-200 CVE-2005-3498: IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain sensitive information.
nvd
CVE-2020-4576P3HIGHCVSS 7.5≥ 7.0.0.0, < 7.0.0.45≥ 8.0.0.0, < 8.0.0.15+6 more2020-10-01
CVE-2020-4576 [HIGH] CVE-2020-4576: IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 184428.
nvd
CVE-2016-2945P3HIGHCVSS 7.5v8.5.5.8v8.5.5.92016-07-08
CVE-2016-2945 [HIGH] CWE-264 CVE-2016-2945: The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 L The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote authenticated users to gain privileges via an external reference in a Swagger document.
nvd
CVE-2018-1770P3MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-10-12
CVE-2018-1770 [MEDIUM] CWE-22 CVE-2018-1770: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse di IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148686.
nvd
CVE-2026-4410P3HIGHCVSS 7.5≥ 8.5.0.0, ≤ 8.5.5.29≥ 9.0.0.0, ≤ 9.0.5.27+3 more2026-05-27
CVE-2026-4410 [HIGH] CWE-400 CVE-2026-4410: IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application S IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2026-9071P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+3 more2026-06-22
CVE-2026-9071 [HIGH] CWE-400 CVE-2026-9071: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0. IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2026-14528P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-07-28
CVE-2026-14528 [HIGH] CWE-532 CVE-2026-14528: IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain se IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
nvd
CVE-2025-36124P3HIGHCVSS 7.5≥ 17.0.0.3, < 25.0.0.92025-08-12
CVE-2025-36124 [HIGH] CWE-268 CVE-2025-36124: IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration
nvd
CVE-2023-50314P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 24.0.0.82024-08-14
CVE-2023-50314 [HIGH] CWE-295 CVE-2023-50314: IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with acce IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274713.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase