Ibm Websphere Application Server vulnerabilities

442 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
442
CISA KEV
1
actively exploited
Public exploits
12
Exploited in wild
2
Severity breakdown
CRITICAL49HIGH92MEDIUM261LOW40

Vulnerabilities

Page 5 of 23
CVE-2020-4464HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-07-17
CVE-2020-4464 [HIGH] CWE-502 CVE-2020-4464: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.
cvelistv5nvd
CVE-2020-4450CRITICALCVSS 9.8Exploited≥ 8.5.0.0, < 8.5.5.18≥ 9.0.0.0, < 9.0.5.5+2 more2020-06-05
CVE-2020-4450 [CRITICAL] CWE-502 CVE-2020-4450: IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute ar IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
cvelistv5nvd
CVE-2020-4448CRITICALCVSS 9.8≥ 8.5.0.0, < 8.5.5.18≥ 9.0.0.0, < 9.0.5.4+4 more2020-06-05
CVE-2020-4448 [CRITICAL] CWE-502 CVE-2020-4448: IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote atta IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.
cvelistv5nvd
CVE-2020-4449HIGHCVSS 7.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-06-05
CVE-2020-4449 [HIGH] CWE-502 CVE-2020-4449: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181230.
cvelistv5nvd
CVE-2020-4365MEDIUMCVSS 4.3≥ 8.5.0.0, ≤ 8.5.5.17v8.52020-05-14
CVE-2020-4365 [MEDIUM] CWE-918 CVE-2020-4365: IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a spec IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.
cvelistv5nvd
CVE-2020-10693MEDIUMCVSS 5.3≥ 17.0.0.3, ≤ 20.0.0.102020-05-06
CVE-2020-10693 [MEDIUM] CWE-20 CVE-2020-10693: A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation proc A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
nvd
CVE-2020-4421MEDIUMCVSS 5.4≥ 19.0.0.5, < 20.0.0.52020-05-06
CVE-2020-4421 [MEDIUM] CWE-290 CVE-2020-4421: IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.
nvd
CVE-2020-4329MEDIUMCVSS 4.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+7 more2020-04-28
CVE-2020-4329 [MEDIUM] CVE-2020-4329: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allo IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenticated attacker to obtain sensitive information, caused by improper parameter checking. This could be exploited to conduct spoofing attacks. IBM X-Force ID: 177841.
cvelistv5nvd
CVE-2020-4362HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-04-10
CVE-2020-4362 [HIGH] CVE-2020-4362: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege esc IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.
cvelistv5nvd
CVE-2020-4304MEDIUMCVSS 6.1≥ 17.0.0.3, ≤ 20.0.0.32020-04-02
CVE-2020-4304 [MEDIUM] CWE-79 CVE-2020-4304: IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scr IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176670.
nvd
CVE-2020-4303MEDIUMCVSS 6.1≥ 17.0.0.3, ≤ 20.0.0.32020-04-02
CVE-2020-4303 [MEDIUM] CWE-79 CVE-2020-4303: IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scr IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176668.
nvd
CVE-2020-4276HIGHCVSS 7.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-03-26
CVE-2020-4276 [HIGH] CVE-2020-4276: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege esc IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.
cvelistv5nvd
CVE-2019-4670MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-02-05
CVE-2019-4670 [MEDIUM] CVE-2019-4670: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sens IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper data representation. IBM X-Force ID: 171319.
cvelistv5nvd
CVE-2020-4163HIGHCVSS 7.2≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-02-04
CVE-2020-4163 [HIGH] CVE-2020-4163: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow a IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397.
cvelistv5nvd
CVE-2019-4732MEDIUMCVSS 6.5v7.0v8.0+2 more2020-02-03
CVE-2019-4732 [MEDIUM] CWE-426 CVE-2019-4732: IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8. IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an att
nvd
CVE-2019-4720HIGHCVSS 7.5fixed in 20.0.0.2≥ 7.0.0.0, ≤ 7.0.0.45+7 more2020-01-31
CVE-2019-4720 [HIGH] CWE-770 CVE-2019-4720: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available memory. IBM X-Force ID: 172125.
cvelistv5nvd
CVE-2019-4663MEDIUMCVSS 5.4≥ 17.0.0.3, < 19.0.0.11vLiberty2019-12-10
CVE-2019-4663 [MEDIUM] CWE-79 CVE-2019-4663: IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171245.
cvelistv5nvd
CVE-2019-4441MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+8 more2019-10-03
CVE-2019-4441 [MEDIUM] CWE-209 CVE-2019-4441: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to ob IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.
cvelistv5nvd
CVE-2019-4305MEDIUMCVSS 5.3fixed in 19.0.0.10vLiberty2019-09-30
CVE-2019-4305 [MEDIUM] CWE-565 CVE-2019-4305: IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive informati IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the improper setting of a cookie. IBM X-Force ID: 160951.
cvelistv5nvd
CVE-2019-4304MEDIUMCVSS 6.3fixed in 19.0.0.10vLiberty2019-09-30
CVE-2019-4304 [MEDIUM] CWE-384 CVE-2019-4304: IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrict IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950.
cvelistv5nvd