cbcvebase.

Ibm Websphere Application Server vulnerabilities

517 known vulnerabilities affecting ibm/websphere_application_server.

Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42

Vulnerabilities

Page 8 of 26
CVE-2025-36097P3HIGHCVSS 7.5≥ 9.0.0.0, < 9.0.5.24≥ 17.0.0.3, < 25.0.0.8+1 more2025-07-16
CVE-2025-36097 [HIGH] CWE-121 CVE-2025-36097: IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0. IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
nvd
CVE-2007-5944P4MEDIUMCVSS 4.3PoCv5.1.1.4v5.1.1.5+11 more2007-11-14
CVE-2007-5944 [MEDIUM] CVE-2007-5944: Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Applicat Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header. NOTE: this might be the same issue as CVE-2006-3918, but there are insufficient details to be sure.
nvd
CVE-2019-4046P3HIGHCVSS 7.5fixed in 19.0.0.4≥ 7.0.0.0, ≤ 7.0.0.45+8 more2019-03-25
CVE-2019-4046 [HIGH] CWE-400 CVE-2019-4046: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handling of request headers. A remote attacker could exploit this vulnerability to cause the consumption of Memory. IBM X-Force ID: 156242.
nvd
CVE-2009-2085P3HIGHCVSS 7.5v6.1v6.1.0+29 more2009-08-13
CVE-2009-2085 [HIGH] CWE-287 CVE-2009-2085: The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB).
nvd
CVE-2009-1172P3CRITICALCVSS 10.0v6.1v6.1.0+25 more2009-03-31
CVE-2009-1172 [CRITICAL] CWE-20 CVE-2009-1172: The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.
nvd
CVE-2001-0122P4MEDIUMCVSS 5.0PoCv3.522001-03-13
CVE-2001-0122 [MEDIUM] CVE-2001-0122: Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
nvd
CVE-2021-20480P3MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+4 more2021-04-08
CVE-2021-20480 [MEDIUM] CWE-918 CVE-2021-20480: IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSR IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197502.
nvd
CVE-2017-1194P3HIGHCVSS 8.8v7.0v8.0+2 more2017-04-28
CVE-2017-1194 [HIGH] CWE-352 CVE-2017-1194: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.
nvd
CVE-2026-11710P3MEDIUMCVSS 6.5v8.52026-09-18
CVE-2026-11710 [MEDIUM] CWE-444 CVE-2026-11710: IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to i IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.
nvd
CVE-2009-1174P3CRITICALCVSS 10.0v7.0v7.0.0.12009-03-31
CVE-2009-1174 [CRITICAL] CWE-310 CVE-2009-1174: The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.
nvd
CVE-2008-2221P3CRITICALCVSS 10.0v5.0.22008-05-14
CVE-2008-2221 [CRITICAL] CVE-2008-2221: Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrus Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack vectors.
nvd
CVE-2007-3263P3CRITICALCVSS 10.0≤ 6.1.0.72007-06-19
CVE-2007-3263 [CRITICAL] CVE-2007-3263: Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WA Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface to the SDO repository."
nvd
CVE-2013-0462P3CRITICALCVSS 10.0v7.0v7.0.0.1+16 more2013-01-27
CVE-2013-0462 [CRITICAL] CVE-2013-0462: Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1, 7.0 before 7.0.0.27, 8.0, a Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1, 7.0 before 7.0.0.27, 8.0, and 8.5 has unknown impact and attack vectors.
nvd
CVE-2009-1901P3CRITICALCVSS 10.0≤ 6.0.2.33v6.0.2+31 more2009-06-03
CVE-2009-1901 [CRITICAL] CVE-2009-1901: The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non- The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact and remote attack vectors.
nvd
CVE-2024-45085P3HIGHCVSS 7.5≥ 8.5.0.0, < 8.5.5.27v8.52024-10-15
CVE-2024-45085 [HIGH] CWE-754 CVE-2024-45085: IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurati IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker could exploit this vulnerability to cause an error resulting in a denial of service.
nvd
CVE-2009-0217P3MEDIUMCVSS 5.0v6.0v6.0.0.1+67 more2009-07-14
CVE-2009-0217 [MEDIUM] CVE-2009-0217: The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented i The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.
nvd
CVE-2001-0390P4MEDIUMCVSS 5.0PoCv5.1.0.32001-07-02
CVE-2001-0390 [MEDIUM] CVE-2001-0390: IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly ca IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
nvd
CVE-2026-15396P3MEDIUMCVSS 6.5v9.0v8.52026-09-14
CVE-2026-15396 [MEDIUM] CWE-444 CVE-2026-15396: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vul IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, byp
nvd
CVE-2026-15634P3MEDIUMCVSS 6.5v9.0v8.52026-09-14
CVE-2026-15634 [MEDIUM] CWE-444 CVE-2026-15634: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vul IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, byp
nvd
CVE-2026-16185P3MEDIUMCVSS 6.4v9.0v8.52026-09-14
CVE-2026-16185 [MEDIUM] CWE-862 CVE-2026-16185: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.
nvd
Ibm Websphere Application Server vulnerabilities | cvebase