Ibm Websphere Application Server vulnerabilities
517 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
517
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL70HIGH119MEDIUM286LOW42
Vulnerabilities
Page 9 of 26
CVE-2006-2430P4CRITICALCVSS 10.0v5.0.0v5.0.1+11 more2006-05-17
CVE-2006-2430 [CRITICAL] CVE-2006-2430: IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 recor
IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.
nvd
CVE-2008-5414P3CRITICALCVSS 10.0v7.02008-12-10
CVE-2008-5414 [CRITICAL] CVE-2008-5414: Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security componen
Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 has unknown impact and attack vectors related to "userNameToken."
nvd
CVE-2009-2092P3HIGHCVSS 7.5v7.0v7.0.0.1+2 more2009-08-13
CVE-2009-2092 [HIGH] CWE-284 CVE-2009-2092: IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingE
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors.
nvd
CVE-2018-1890P3HIGHCVSS 7.8v7.0v8.0+3 more2019-03-11
CVE-2018-1890 [HIGH] CWE-427 CVE-2018-1890: IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facili
IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 152081.
nvd
CVE-2013-3024P3HIGHCVSS 7.8≥ 8.5.0.0, ≤ 8.5.0.22018-05-24
CVE-2013-3024 [HIGH] CWE-264 CVE-2013-3024: IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privil
IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initialization. IBM X-Force ID: 84362.
nvd
CVE-2026-9667P3MEDIUMCVSS 5.3≥ 8.5.0.0, < 8.5.5.31≥ 9.0.0.0, < 9.0.5.29+2 more2026-09-10
CVE-2026-9667 [MEDIUM] CWE-918 CVE-2026-9667: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) th
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.
nvd
CVE-2025-33104P3HIGHCVSS 7.6≥ 8.5, < 8.5.5.28≥ 9.0, < 9.0.5.24+1 more2025-05-14
CVE-2025-33104 [HIGH] CWE-79 CVE-2025-33104: IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerabili
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2014-4767P3MEDIUMCVSS 6.5v8.5.0.0v8.5.0.1+4 more2014-08-22
CVE-2014-4767 [MEDIUM] CWE-94 CVE-2014-4767: IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use th
IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-3305P3MEDIUMCVSS 6.4v6.1v6.1.0+62 more2012-09-25
CVE-2012-3305 [MEDIUM] CWE-22 CVE-2012-3305: Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0
Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a crafted application file.
nvd
CVE-2019-4670P3MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2020-02-05
CVE-2019-4670 [MEDIUM] CVE-2019-4670: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sens
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper data representation. IBM X-Force ID: 171319.
nvd
CVE-2016-8919P4HIGHCVSS 7.5v7.0v8.0+2 more2017-02-01
CVE-2016-8919 [HIGH] CWE-399 CVE-2016-8919: IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serial
IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and cause the consumption of resources.
nvd
CVE-2007-6679P3CRITICALCVSS 10.0≤ 6.0.2.24v6.1+7 more2008-01-10
CVE-2007-6679 [CRITICAL] CVE-2007-6679: Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 befo
Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 before Fix Pack 13 has unknown impact and attack vectors, related to "security concerns with monitor role users." NOTE: it was later reported that 6.0.2 before Fix Pack 25 is also affected.
nvd
CVE-2026-5516P3MEDIUMCVSS 5.9≥ 22.0.0.11, ≤ 26.0.0.52026-05-27
CVE-2026-5516 [MEDIUM] CWE-362 CVE-2026-5516: IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Serv
IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.
nvd
CVE-2026-11539P3MEDIUMCVSS 5.3v9.0v8.52026-09-18
CVE-2026-11539 [MEDIUM] CWE-306 CVE-2026-11539: IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability i
IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.
nvd
CVE-2018-1755P4MEDIUMCVSS 5.9vLiberty2018-08-24
CVE-2018-1755 [MEDIUM] CWE-200 CVE-2018-1755: IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive informati
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC). This can happen when the Application Server is configured to permit access on non-secure (http) port and using JASPIC or JSR3
nvd
CVE-2026-15412P4MEDIUMCVSS 6.5v9.0v8.52026-09-14
CVE-2026-15412 [MEDIUM] CWE-601 CVE-2026-15412: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could a
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a mali
nvd
CVE-2026-3621P4MEDIUMCVSS 5.9≥ 17.0.0.3, < 26.0.0.52026-04-23
CVE-2026-3621 [MEDIUM] CWE-269 CVE-2026-3621: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Serve
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.
nvd
CVE-2006-6136P4CRITICALCVSS 10.0v6.1.02006-11-28
CVE-2006-6136 [CRITICAL] CVE-2006-6136: IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authenticat
IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authentication checks at the proper time during "registering of response operation," which has unknown impact and attack vectors.
nvd
CVE-2009-0391P4HIGHCVSS 7.8v6.0.12009-02-02
CVE-2009-0391 [HIGH] CWE-200 CVE-2009-0391: Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers t
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.
nvd
CVE-2026-1561P4MEDIUMCVSS 5.4≥ 17.0.0.3, < 26.0.0.42026-03-25
CVE-2026-1561 [MEDIUM] CWE-918 CVE-2026-1561: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Serve
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd