Ibm Websphere Application Server vulnerabilities
467 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40
Vulnerabilities
Page 8 of 24
CVE-2018-1755P4MEDIUMCVSS 5.9vLiberty2018-08-24
CVE-2018-1755 [MEDIUM] CWE-200 CVE-2018-1755: IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive informati
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC). This can happen when the Application Server is configured to permit access on non-secure (http) port and using JASPIC or JSR3
nvd
CVE-2016-8919P4HIGHCVSS 7.5v7.0v8.0+2 more2017-02-01
CVE-2016-8919 [HIGH] CWE-399 CVE-2016-8919: IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serial
IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and cause the consumption of resources.
nvd
CVE-2006-6136P4CRITICALCVSS 10.0v6.1.02006-11-28
CVE-2006-6136 [CRITICAL] CVE-2006-6136: IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authenticat
IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authentication checks at the proper time during "registering of response operation," which has unknown impact and attack vectors.
nvd
CVE-2026-3621P4MEDIUMCVSS 5.9≥ 17.0.0.3, < 26.0.0.52026-04-23
CVE-2026-3621 [MEDIUM] CWE-269 CVE-2026-3621: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Serve
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.
nvd
CVE-2009-0391P4HIGHCVSS 7.8v6.0.12009-02-02
CVE-2009-0391 [HIGH] CWE-200 CVE-2009-0391: Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers t
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.
nvd
CVE-2006-6135P4CRITICALCVSS 10.0v6.1.02006-11-28
CVE-2006-6135 [CRITICAL] CVE-2006-6135: Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.
Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, related to (1) a "Potential security vulnerability" (PK29725) and (2) "Potential security exposure" (PK30831).
nvd
CVE-2013-0543P4MEDIUMCVSS 6.8v6.1.0.0v6.1.0.1+51 more2013-04-24
CVE-2013-0543 [MEDIUM] CWE-863 CVE-2013-0543: IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6,
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2018-1838P4MEDIUMCVSS 6.5v8.5.0.0v9.0.0.0+2 more2018-10-12
CVE-2018-1838 [MEDIUM] CWE-200 CVE-2018-1838: IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain se
IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords. IBM X-Force ID: 150811.
nvd
CVE-2022-22310P4MEDIUMCVSS 6.5≥ 21.0.0.10, ≤ 21.0.0.122022-01-19
CVE-2022-22310 [MEDIUM] CVE-2022-22310: IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expec
IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 217224.
nvd
CVE-2015-0110P4MEDIUMCVSS 6.5v7.2.0.0v7.2.0.1+4 more2017-09-15
CVE-2015-0110 [MEDIUM] CWE-284 CVE-2015-0110: IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka W
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to bypass intended access restrictions on internal service types via vectors involving the executeServiceByName URL.
nvd
CVE-2022-22393P4MEDIUMCVSS 6.5≥ 17.0.0.3, ≤ 22.0.0.52022-05-13
CVE-2022-22393 [MEDIUM] CVE-2022-22393: IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 featur
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could allow an authenticated user to issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server. IBM X-Force ID: 222078.
nvd
CVE-2005-1872P4HIGHCVSS 7.5v5.02005-06-03
CVE-2005-1872 [HIGH] CVE-2005-1872: Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the glob
Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.
nvd
CVE-2019-4268P4MEDIUMCVSS 5.3≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-09-17
CVE-2019-4268 [MEDIUM] CWE-22 CVE-2019-4268: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse di
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 160201.
nvd
CVE-2006-6636P4CRITICALCVSS 10.0v5.1.1v5.1.1.1+18 more2006-12-19
CVE-2006-6636 [CRITICAL] CVE-2006-6636: Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5
Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.
nvd
CVE-2008-3235P4CRITICALCVSS 10.0v5.1.0v5.1.1+18 more2008-07-21
CVE-2008-3235 [CRITICAL] CWE-255 CVE-2008-3235: Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM We
Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 has unknown impact and attack vectors.
nvd
CVE-2006-2436P4HIGHCVSS 7.5v5.0.0v5.0.1+1 more2006-05-17
CVE-2006-2436 [HIGH] CVE-2006-2436: WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords i
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.
nvd
CVE-2026-1561P4MEDIUMCVSS 5.4≥ 17.0.0.3, < 26.0.0.42026-03-25
CVE-2026-1561 [MEDIUM] CWE-918 CVE-2026-1561: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Serve
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2008-4111P4CRITICALCVSS 9.3v6.1v6.1.0+19 more2008-09-16
CVE-2008-4111 [CRITICAL] CVE-2008-4111: Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS)
Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when the FileServing feature is enabled, has unknown impact and attack vectors.
nvd
CVE-2015-1927P4MEDIUMCVSS 6.8v7.0v7.0.0.1+52 more2015-07-14
CVE-2015-1927 [MEDIUM] CWE-284 CVE-2015-1927: The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 bef
The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors.
nvd
CVE-2019-4477P4MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-09-17
CVE-2019-4477 [MEDIUM] CWE-269 CVE-2019-4477: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive information, caused by improper handling of command line options. IBM X-Force ID: 163997.
nvd