cbcvebase.

Ibm Websphere Application Server vulnerabilities

517 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42

Vulnerabilities

Page 6 of 26
CVE-2015-1882P3HIGHCVSS 8.5v8.5.0.0v8.5.0.1+6 more2015-04-27
CVE-2015-1882 [HIGH] CWE-362 CVE-2015-1882: Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5. Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.
nvd
CVE-2026-11707P3CRITICALCVSS 9.3≥ 8.5, < 8.5.5.30≥ 9.0, < 9.0.5.292026-07-30
CVE-2026-11707 [CRITICAL] CWE-79 CVE-2026-11707: IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affecte IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
nvd
CVE-2009-1899P3CRITICALCVSS 10.0≤ 6.0.2.33v6.0.2+31 more2009-06-03
CVE-2009-1899 [CRITICAL] CVE-2009-1899: Unspecified vulnerability in the Administrative Configservice API in the System Management/Repositor Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5 on z/OS allows remote authenticated users to obtain sensitive information via unknown use of the wsadmin scripting tool, related to a "sec
nvd
CVE-2018-1926P3HIGHCVSS 8.8≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2018-12-12
CVE-2018-1926 [HIGH] CWE-352 CVE-2018-1926: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site re IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious URL, a remote attacker could send a specially-crafted request. An attacker could exploit this vulnerability to perform CSRF attack and update av
nvd
CVE-2018-1553P3HIGHCVSS 7.5fixed in 18.0.0.22018-06-27
CVE-2018-1553 [HIGH] CWE-200 CVE-2018-1553: IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain s IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature. IBM X-Force ID: 142890.
nvd
CVE-2018-1905P3HIGHCVSS 7.1≥ 9.0.0.0, ≤ 9.0.0.9v9.0.0.0+6 more2018-11-26
CVE-2018-1905 [HIGH] CWE-611 CVE-2018-1905: IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Inje IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152534.
nvd
CVE-2025-14914P3HIGHCVSS 7.6≥ 17.0.0.3, ≤ 26.0.0.12026-02-02
CVE-2025-14914 [HIGH] CWE-22 CVE-2025-14914: IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.
nvd
CVE-2026-9320P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.30≥ 9.0.0.0, < 9.0.5.29+3 more2026-06-22
CVE-2026-9320 [HIGH] CWE-400 CVE-2026-9320: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0. IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2026-11897P3HIGHCVSS 7.5≥ 17.0.0.3, < 26.0.0.82026-07-30
CVE-2026-11897 [HIGH] CWE-770 CVE-2026-11897: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of se IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2020-4782P3MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-10-28
CVE-2020-4782 [MEDIUM] CWE-22 CVE-2020-4782: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse di IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
nvd
CVE-2006-2431P4MEDIUMCVSS 4.3PoCv5.0.0v5.0.1+18 more2006-05-17
CVE-2006-2431 [MEDIUM] CWE-79 CVE-2006-2431: Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (888 Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some
nvd
CVE-2009-0508P3HIGHCVSS 7.5v5.1.0v5.1.1.19+32 more2009-03-16
CVE-2009-0508 [HIGH] CWE-200 CVE-2009-0508: The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-bas
nvd
CVE-2018-1614P3HIGHCVSS 7.5v7.0v8.0+2 more2018-06-26
CVE-2018-1614 [HIGH] CWE-200 CVE-2018-1614: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker to obtain sensitive information. IBM X-Force ID: 144270.
nvd
CVE-2016-5986P3HIGHCVSS 7.5v7.0v7.0.0.0+66 more2016-10-01
CVE-2016-5986 [HIGH] CWE-200 CVE-2016-5986: IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5. IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2018-1683P3HIGHCVSS 7.5fixed in 18.0.0.3vunspecified2018-09-26
CVE-2018-1683 [HIGH] CWE-311 CVE-2018-1683: IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive informati IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455.
nvd
CVE-2016-9879P3HIGHCVSS 7.5v8.5.0.0v8.5.0.1+11 more2017-01-06
CVE-2016-9879 [HIGH] CWE-417 CVE-2016-9879: An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x befo An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a request, an attacker may be able to bypass a security constraint. The root cause of this issue is
nvd
CVE-2024-27268P3HIGHCVSS 7.5≥ 18.0.0.2, < 24.0.0.52024-04-04
CVE-2024-27268 [HIGH] CWE-770 CVE-2024-27268: IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of serv IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 284574.
nvd
CVE-2024-25026P3HIGHCVSS 7.5≥ 8.5.0.0, ≤ 8.5.5.25≥ 9.0.0.0, ≤ 9.0.5.19+2 more2024-04-25
CVE-2024-25026 [HIGH] CWE-770 CVE-2024-25026: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 281516.
nvd
CVE-2026-10852P3HIGHCVSS 7.5v8.5v9.02026-06-22
CVE-2026-10852 [HIGH] CWE-476 CVE-2026-10852: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to deni IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.
nvd
CVE-2024-22354P3HIGHCVSS 7.0≥ 8.5.0.0, < 8.5.5.26≥ 9.0.0.0, < 9.0.5.20+2 more2024-04-17
CVE-2024-22354 [HIGH] CWE-611 CVE-2024-22354: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forg
nvd
Ibm Websphere Application Server vulnerabilities | cvebase