Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 7 of 26
CVE-2011-1377P3CRITICALCVSS 10.0v6.1v6.1.0+29 more2012-01-15
CVE-2011-1377 [CRITICAL] CVE-2011-1377: The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphe
The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.
nvd
CVE-2012-4850P3HIGHCVSS 7.5v8.5.0.02012-11-14
CVE-2012-4850 [HIGH] CWE-20 CVE-2012-4850: IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not p
IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote attackers to gain privileges via unspecified vectors.
nvd
CVE-2016-2923P3HIGHCVSS 7.5v8.5.5.0v8.5.5.1+8 more2016-07-07
CVE-2016-2923 [HIGH] CWE-200 CVE-2016-2923: IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2
IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified JAX-RS API cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
nvd
CVE-2009-0903P3HIGHCVSS 7.5v6.1v6.1.0+27 more2009-06-25
CVE-2009-0903 [HIGH] CVE-2009-0903: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted
nvd
CVE-2021-38951P3HIGHCVSS 7.5v7.0v8.0+2 more2021-12-09
CVE-2021-38951 [HIGH] CVE-2021-38951: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405.
nvd
CVE-2024-22353P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 24.0.0.32024-03-31
CVE-2024-22353 [HIGH] CWE-770 CVE-2024-22353: IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of serv
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 280400.
nvd
CVE-2020-4163P3HIGHCVSS 7.2≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-02-04
CVE-2020-4163 [HIGH] CVE-2020-4163: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow a
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397.
nvd
CVE-2026-9322P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+3 more2026-07-30
CVE-2026-9322 [HIGH] CWE-400 CVE-2026-9322: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
nvd
CVE-2022-43917P3HIGHCVSS 7.5v8.5v9.0+1 more2023-01-26
CVE-2022-43917 [HIGH] CWE-327 CVE-2022-43917: IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected crypto
IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information. This affects only the containerized version of WebSphere Application Server traditional. IBM X-Force ID: 241045.
nvd
CVE-2025-36047P3HIGHCVSS 7.5≥ 18.0.0.2, < 25.0.0.92025-08-14
CVE-2025-36047 [HIGH] CWE-770 CVE-2025-36047: IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of serv
IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2025-33142P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.29≥ 9.0.0.0, < 9.0.5.25+2 more2025-08-14
CVE-2025-33142 [HIGH] CWE-295 CVE-2025-33142: IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS con
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
nvd
CVE-2020-5016P3MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2021-03-10
CVE-2020-5016 [MEDIUM] CWE-22 CVE-2020-5016: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse di
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. When application security is disabled and JAX-RPC applications are present, an attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary xml files on the system. This does not occ
nvd
CVE-2026-9176P3HIGHCVSS 7.1≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-09-10
CVE-2026-9176 [HIGH] CWE-94 CVE-2026-9176: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper aut
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.
nvd
CVE-2010-3186P3CRITICALCVSS 10.0v7.0v7.0.0.1+31 more2010-08-30
CVE-2010-3186 [CRITICAL] CWE-20 CVE-2010-3186: IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.
nvd
CVE-2026-16435P3MEDIUMCVSS 5.9v9.0v8.52026-09-14
CVE-2026-16435 [MEDIUM] CWE-650 CVE-2026-16435: IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.
nvd
CVE-2019-4720P3HIGHCVSS 7.5fixed in 20.0.0.2≥ 7.0.0.0, ≤ 7.0.0.45+7 more2020-01-31
CVE-2019-4720 [HIGH] CWE-770 CVE-2019-4720: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available memory. IBM X-Force ID: 172125.
nvd
CVE-2023-38737P3HIGHCVSS 7.5≥ 22.0.0.13, ≤ 23.0.0.72023-08-16
CVE-2023-38737 [HIGH] CWE-20 CVE-2023-38737: IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of ser
IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 262567.
nvd
CVE-2023-30441P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.23v9.0.0.02023-04-29
CVE-2023-30441 [HIGH] CWE-327 CVE-2023-30441: IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 compon
IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188.
nvd
CVE-2026-15057P3HIGHCVSS 7.5≥ 17.0.0.3, < 26.0.0.82026-07-28
CVE-2026-15057 [HIGH] CWE-787 CVE-2026-15057: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of se
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
nvd
CVE-2026-14981P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+3 more2026-07-28
CVE-2026-14981 [HIGH] CWE-400 CVE-2026-14981: IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a de
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
nvd