cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 5 of 24
CVE-2015-1882P3HIGHCVSS 8.5v8.5.0.0v8.5.0.1+6 more2015-04-27
CVE-2015-1882 [HIGH] CWE-362 CVE-2015-1882: Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5. Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.
nvd
CVE-2009-1899P3CRITICALCVSS 10.0≤ 6.0.2.33v6.0.2+31 more2009-06-03
CVE-2009-1899 [CRITICAL] CVE-2009-1899: Unspecified vulnerability in the Administrative Configservice API in the System Management/Repositor Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5 on z/OS allows remote authenticated users to obtain sensitive information via unknown use of the wsadmin scripting tool, related to a "sec
nvd
CVE-2018-1926P3HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-12-12
CVE-2018-1926 [HIGH] CWE-352 CVE-2018-1926: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site re IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious URL, a remote attacker could send a specially-crafted request. An attacker could exploit this vulnerability to perform CSRF attack and update av
nvd
CVE-2018-1905P3HIGHCVSS 7.1≥ 9.0.0.0, ≤ 9.0.0.9v9.0.0.0+6 more2018-11-26
CVE-2018-1905 [HIGH] CWE-611 CVE-2018-1905: IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Inje IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152534.
nvd
CVE-2018-1770P3MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-10-12
CVE-2018-1770 [MEDIUM] CWE-22 CVE-2018-1770: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse di IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148686.
nvd
CVE-2025-14914P3HIGHCVSS 7.6≥ 17.0.0.3, ≤ 26.0.0.12026-02-02
CVE-2025-14914 [HIGH] CWE-22 CVE-2025-14914: IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.
nvd
CVE-2006-2431P4MEDIUMCVSS 4.3PoCv5.0.0v5.0.1+18 more2006-05-17
CVE-2006-2431 [MEDIUM] CWE-79 CVE-2006-2431: Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (888 Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some
nvd
CVE-2024-22354P3HIGHCVSS 7.0≥ 8.5.0.0, < 8.5.5.26≥ 9.0.0.0, < 9.0.5.20+2 more2024-04-17
CVE-2024-22354 [HIGH] CWE-611 CVE-2024-22354: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forg
nvd
CVE-2018-1553P3HIGHCVSS 7.5fixed in 18.0.0.22018-06-27
CVE-2018-1553 [HIGH] CWE-200 CVE-2018-1553: IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain s IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature. IBM X-Force ID: 142890.
nvd
CVE-2016-5986P3HIGHCVSS 7.5v7.0v7.0.0.0+66 more2016-10-01
CVE-2016-5986 [HIGH] CWE-200 CVE-2016-5986: IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5. IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2024-27268P3HIGHCVSS 7.5≥ 18.0.0.2, < 24.0.0.52024-04-04
CVE-2024-27268 [HIGH] CWE-770 CVE-2024-27268: IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of serv IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 284574.
nvd
CVE-2024-25026P3HIGHCVSS 7.5≥ 8.5.0.0, ≤ 8.5.5.25≥ 9.0.0.0, ≤ 9.0.5.19+2 more2024-04-25
CVE-2024-25026 [HIGH] CWE-770 CVE-2024-25026: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 281516.
nvd
CVE-2026-9320P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+3 more2026-06-22
CVE-2026-9320 [HIGH] CWE-400 CVE-2026-9320: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0. IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2025-33142P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.29≥ 9.0.0.0, < 9.0.5.25+2 more2025-08-14
CVE-2025-33142 [HIGH] CWE-295 CVE-2025-33142: IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS con IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
nvd
CVE-2009-0508P3HIGHCVSS 7.5v5.1.0v5.1.1.19+32 more2009-03-16
CVE-2009-0508 [HIGH] CWE-200 CVE-2009-0508: The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-bas
nvd
CVE-2018-1614P3HIGHCVSS 7.5v7.0v8.0+2 more2018-06-26
CVE-2018-1614 [HIGH] CWE-200 CVE-2018-1614: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker to obtain sensitive information. IBM X-Force ID: 144270.
nvd
CVE-2011-1377P3CRITICALCVSS 10.0v6.1v6.1.0+29 more2012-01-15
CVE-2011-1377 [CRITICAL] CVE-2011-1377: The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphe The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.
nvd
CVE-2012-4850P3HIGHCVSS 7.5v8.5.0.02012-11-14
CVE-2012-4850 [HIGH] CWE-20 CVE-2012-4850: IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not p IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote attackers to gain privileges via unspecified vectors.
nvd
CVE-2016-2923P3HIGHCVSS 7.5v8.5.5.0v8.5.5.1+8 more2016-07-07
CVE-2016-2923 [HIGH] CWE-200 CVE-2016-2923: IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified JAX-RS API cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
nvd
CVE-2009-0903P3HIGHCVSS 7.5v6.1v6.1.0+27 more2009-06-25
CVE-2009-0903 [HIGH] CVE-2009-0903: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted
nvd
Ibm Websphere Application Server vulnerabilities | cvebase