Ibm Websphere Application Server vulnerabilities
467 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40
Vulnerabilities
Page 6 of 24
CVE-2018-1683P3HIGHCVSS 7.5fixed in 18.0.0.3vunspecified2018-09-26
CVE-2018-1683 [HIGH] CWE-311 CVE-2018-1683: IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive informati
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455.
nvd
CVE-2019-4720P3HIGHCVSS 7.5fixed in 20.0.0.2≥ 7.0.0.0, ≤ 7.0.0.45+7 more2020-01-31
CVE-2019-4720 [HIGH] CWE-770 CVE-2019-4720: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available memory. IBM X-Force ID: 172125.
nvd
CVE-2016-9879P3HIGHCVSS 7.5v8.5.0.0v8.5.0.1+11 more2017-01-06
CVE-2016-9879 [HIGH] CWE-417 CVE-2016-9879: An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x befo
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a request, an attacker may be able to bypass a security constraint. The root cause of this issue is
nvd
CVE-2024-22353P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 24.0.0.32024-03-31
CVE-2024-22353 [HIGH] CWE-770 CVE-2024-22353: IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of serv
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 280400.
nvd
CVE-2023-38737P3HIGHCVSS 7.5≥ 22.0.0.13, ≤ 23.0.0.72023-08-16
CVE-2023-38737 [HIGH] CWE-20 CVE-2023-38737: IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of ser
IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 262567.
nvd
CVE-2022-43917P3HIGHCVSS 7.5v8.5v9.0+1 more2023-01-26
CVE-2022-43917 [HIGH] CWE-327 CVE-2022-43917: IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected crypto
IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information. This affects only the containerized version of WebSphere Application Server traditional. IBM X-Force ID: 241045.
nvd
CVE-2025-36047P3HIGHCVSS 7.5≥ 18.0.0.2, < 25.0.0.92025-08-14
CVE-2025-36047 [HIGH] CWE-770 CVE-2025-36047: IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of serv
IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2026-10852P3HIGHCVSS 7.5v8.5v9.02026-06-22
CVE-2026-10852 [HIGH] CWE-476 CVE-2026-10852: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to deni
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.
nvd
CVE-2020-5016P3MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-03-10
CVE-2020-5016 [MEDIUM] CWE-22 CVE-2020-5016: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse di
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. When application security is disabled and JAX-RPC applications are present, an attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary xml files on the system. This does not occ
nvd
CVE-2007-5944P4MEDIUMCVSS 4.3PoCv5.1.1.4v5.1.1.5+11 more2007-11-14
CVE-2007-5944 [MEDIUM] CVE-2007-5944: Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Applicat
Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header. NOTE: this might be the same issue as CVE-2006-3918, but there are insufficient details to be sure.
nvd
CVE-2010-3186P3CRITICALCVSS 10.0v7.0v7.0.0.1+31 more2010-08-30
CVE-2010-3186 [CRITICAL] CWE-20 CVE-2010-3186: IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.
nvd
CVE-2021-38951P3HIGHCVSS 7.5v7.0v8.0+2 more2021-12-09
CVE-2021-38951 [HIGH] CVE-2021-38951: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405.
nvd
CVE-2020-4163P3HIGHCVSS 7.2≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-02-04
CVE-2020-4163 [HIGH] CVE-2020-4163: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow a
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397.
nvd
CVE-2023-30441P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.23v9.0.0.02023-04-29
CVE-2023-30441 [HIGH] CWE-327 CVE-2023-30441: IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 compon
IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188.
nvd
CVE-2025-36097P3HIGHCVSS 7.5≥ 9.0.0.0, < 9.0.5.24≥ 17.0.0.3, < 25.0.0.8+1 more2025-07-16
CVE-2025-36097 [HIGH] CWE-121 CVE-2025-36097: IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
nvd
CVE-2019-4046P3HIGHCVSS 7.5fixed in 19.0.0.4≥ 7.0.0.0, ≤ 7.0.0.45+8 more2019-03-25
CVE-2019-4046 [HIGH] CWE-400 CVE-2019-4046: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handling of request headers. A remote attacker could exploit this vulnerability to cause the consumption of Memory. IBM X-Force ID: 156242.
nvd
CVE-2009-2085P3HIGHCVSS 7.5v6.1v6.1.0+29 more2009-08-13
CVE-2009-2085 [HIGH] CWE-287 CVE-2009-2085: The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before
The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).
nvd
CVE-2009-1172P3CRITICALCVSS 10.0v6.1v6.1.0+25 more2009-03-31
CVE-2009-1172 [CRITICAL] CWE-20 CVE-2009-1172: The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application
The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.
nvd
CVE-2001-0122P4MEDIUMCVSS 5.0PoCv3.522001-03-13
CVE-2001-0122 [MEDIUM] CVE-2001-0122: Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
nvd
CVE-2021-20480P3MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+4 more2021-04-08
CVE-2021-20480 [MEDIUM] CWE-918 CVE-2021-20480: IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSR
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197502.
nvd