cbcvebase.

Ibm Websphere Application Server vulnerabilities

467 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40

Vulnerabilities

Page 7 of 24
CVE-2017-1194P3HIGHCVSS 8.8v7.0v8.0+2 more2017-04-28
CVE-2017-1194 [HIGH] CWE-352 CVE-2017-1194: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.
nvd
CVE-2001-0390P4MEDIUMCVSS 5.0PoCv5.1.0.32001-07-02
CVE-2001-0390 [MEDIUM] CVE-2001-0390: IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly ca IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
nvd
CVE-2006-2430P3CRITICALCVSS 10.0v5.0.0v5.0.1+11 more2006-05-17
CVE-2006-2430 [CRITICAL] CVE-2006-2430: IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 recor IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
nvd
CVE-2009-1174P3CRITICALCVSS 10.0v7.0v7.0.0.12009-03-31
CVE-2009-1174 [CRITICAL] CWE-310 CVE-2009-1174: The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.
nvd
CVE-2008-2221P3CRITICALCVSS 10.0v5.0.22008-05-14
CVE-2008-2221 [CRITICAL] CVE-2008-2221: Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrus Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack vectors.
nvd
CVE-2008-5414P3CRITICALCVSS 10.0v7.02008-12-10
CVE-2008-5414 [CRITICAL] CVE-2008-5414: Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security componen Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 has unknown impact and attack vectors related to "userNameToken."
nvd
CVE-2007-3263P3CRITICALCVSS 10.0≤ 6.1.0.72007-06-19
CVE-2007-3263 [CRITICAL] CVE-2007-3263: Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WA Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface to the SDO repository."
nvd
CVE-2013-0462P3CRITICALCVSS 10.0v7.0v7.0.0.1+16 more2013-01-27
CVE-2013-0462 [CRITICAL] CVE-2013-0462: Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1, 7.0 before 7.0.0.27, 8.0, a Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1, 7.0 before 7.0.0.27, 8.0, and 8.5 has unknown impact and attack vectors.
nvd
CVE-2018-1890P3HIGHCVSS 7.8v7.0v8.0+3 more2019-03-11
CVE-2018-1890 [HIGH] CWE-427 CVE-2018-1890: IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facili IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 152081.
nvd
CVE-2024-45085P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.27v8.52024-10-15
CVE-2024-45085 [HIGH] CWE-754 CVE-2024-45085: IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurati IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker could exploit this vulnerability to cause an error resulting in a denial of service.
nvd
CVE-2007-6679P3CRITICALCVSS 10.0≤ 6.0.2.24v6.1+7 more2008-01-10
CVE-2007-6679 [CRITICAL] CVE-2007-6679: Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 befo Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 before Fix Pack 13 has unknown impact and attack vectors, related to "security concerns with monitor role users." NOTE: it was later reported that 6.0.2 before Fix Pack 25 is also affected.
nvd
CVE-2009-1901P4CRITICALCVSS 10.0≤ 6.0.2.33v6.0.2+31 more2009-06-03
CVE-2009-1901 [CRITICAL] CVE-2009-1901: The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non- The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact and remote attack vectors.
nvd
CVE-2009-2092P3HIGHCVSS 7.5v7.0v7.0.0.1+2 more2009-08-13
CVE-2009-2092 [HIGH] CWE-284 CVE-2009-2092: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingE IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors.
nvd
CVE-2013-3024P3HIGHCVSS 7.8≥ 8.5.0.0, ≤ 8.5.0.22018-05-24
CVE-2013-3024 [HIGH] CWE-264 CVE-2013-3024: IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privil IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initialization. IBM X-Force ID: 84362.
nvd
CVE-2025-33104P3HIGHCVSS 7.6≥ 8.5, < 8.5.5.28≥ 9.0, < 9.0.5.24+1 more2025-05-14
CVE-2025-33104 [HIGH] CWE-79 CVE-2025-33104: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2014-4767P3MEDIUMCVSS 6.5v8.5.0.0v8.5.0.1+4 more2014-08-22
CVE-2014-4767 [MEDIUM] CWE-94 CVE-2014-4767: IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use th IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
nvd
CVE-2009-0217P3MEDIUMCVSS 5.0v6.0v6.0.0.1+67 more2009-07-14
CVE-2009-0217 [MEDIUM] CVE-2009-0217: The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented i The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.
nvd
CVE-2019-4670P3MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-02-05
CVE-2019-4670 [MEDIUM] CVE-2019-4670: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sens IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper data representation. IBM X-Force ID: 171319.
nvd
CVE-2026-5516P3MEDIUMCVSS 5.9≥ 22.0.0.11, ≤ 26.0.0.52026-05-27
CVE-2026-5516 [MEDIUM] CWE-362 CVE-2026-5516: IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Serv IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.
nvd
CVE-2012-3305P4MEDIUMCVSS 6.4v6.1v6.1.0+62 more2012-09-25
CVE-2012-3305 [MEDIUM] CWE-22 CVE-2012-3305: Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a crafted application file.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase