Ibm Websphere Application Server vulnerabilities
467 known vulnerabilities affecting ibm/websphere_application_server.
Total CVEs
467
CISA KEV
1
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL61HIGH102MEDIUM264LOW40
Vulnerabilities
Page 9 of 24
CVE-2022-22475P4MEDIUMCVSS 6.5≥ 17.0.0.3, ≤ 22.0.0.52022-05-17
CVE-2022-22475 [MEDIUM] CVE-2022-22475: IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable t
IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM X-Force ID: 225603.
nvd
CVE-2019-4304P4MEDIUMCVSS 6.3fixed in 19.0.0.10vLiberty2019-09-30
CVE-2019-4304 [MEDIUM] CWE-384 CVE-2019-4304: IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrict
IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950.
nvd
CVE-2008-5412P4CRITICALCVSS 10.0≤ 7.02008-12-10
CVE-2008-5412 [CRITICAL] CVE-2008-5412: Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs. NOTE: this is probably a duplicate of CVE-2009-0438.
nvd
CVE-2006-2429P4CRITICALCVSS 10.0v6.0.2v6.0.2.1+3 more2006-05-17
CVE-2006-2429 [CRITICAL] CVE-2006-2429: Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers".
nvd
CVE-2007-5483P4CRITICALCVSS 10.0v5.1.1v5.1.1.1+31 more2007-10-16
CVE-2007-5483 [CRITICAL] CVE-2007-5483: Unspecified vulnerability in the Administrative Scripting Tools (such as wsadmin or ANT) in IBM WebS
Unspecified vulnerability in the Administrative Scripting Tools (such as wsadmin or ANT) in IBM WebSphere Application Server 5.x and 6.0.x has unknown impact and attack vectors.
nvd
CVE-2008-0741P4CRITICALCVSS 10.0≤ 6.0.2.242008-02-13
CVE-2008-0741 [CRITICAL] CWE-264 CVE-2008-0741: Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server
Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has unknown impact and attack vectors.
nvd
CVE-2007-1608P4HIGHCVSS 7.5≤ 6.0.2.152007-03-22
CVE-2007-1608 [HIGH] CVE-2007-1608: CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.
nvd
CVE-2019-4080P4MEDIUMCVSS 6.5≥ 7.0.0.0, ≤ 7.0.0.45≥ 8.0.0.0, ≤ 8.0.0.15+6 more2019-04-02
CVE-2019-4080 [MEDIUM] CWE-400 CVE-2019-4080: IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential d
IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter parsing. A remote attacker could exploit this to consume all available CPU resources. IBM X-Force ID: 157380.
nvd
CVE-2012-3304P4MEDIUMCVSS 6.8v6.1.0v6.1.0.0+49 more2012-09-25
CVE-2012-3304 [MEDIUM] CVE-2012-3304: The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before
The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors.
nvd
CVE-2016-2960P4LOWCVSS 3.7v7.0v7.0.0.0+64 more2016-08-08
CVE-2016-2960 [LOW] CWE-284 CVE-2016-2960: IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.
nvd
CVE-2017-1382P4HIGHCVSS 7.1≥ 7.0.0.0, ≤ 7.0.0.43≥ 8.0.0.0, ≤ 8.0.0.13+6 more2017-07-24
CVE-2017-1382 [HIGH] CWE-276 CVE-2017-1382: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permiss
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.
nvd
CVE-2009-0904P4MEDIUMCVSS 6.4v6.1v6.1.0+26 more2009-07-05
CVE-2009-0904 [MEDIUM] CWE-264 CVE-2009-0904: The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS)
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.
nvd
CVE-2017-1504P4MEDIUMCVSS 6.5v9.0.0.4v9.02017-08-03
CVE-2017-1504 [MEDIUM] CVE-2017-1504: IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after u
IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES password encryption. IBM X-Force ID: 129579.
nvd
CVE-2018-1719P4MEDIUMCVSS 5.9≥ 8.5.0.0, ≤ 8.5.5.14≥ 9.0.0.0, ≤ 9.0.0.8+2 more2018-09-14
CVE-2018-1719 [MEDIUM] CVE-2018-1719: IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certa
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This could result in a downgrade of TLS protocol. A remote attacker could exploit this vulnerability to perform man-in-the-middle attacks. IBM X-Force ID: 147292.
nvd
CVE-2008-4678P4HIGHCVSS 7.8v6.0.2v6.0.2.1+14 more2008-10-22
CVE-2008-4678 [HIGH] CWE-399 CVE-2008-4678: The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (
The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."
nvd
CVE-2006-7198P4CRITICALCVSS 10.0v5.1.1.14≤ 6.0.2.112007-04-30
CVE-2006-7198 [CRITICAL] CVE-2006-7198: Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/O
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and attack vectors, related to a "Potential security exposure," aka PK26123.
nvd
CVE-2008-0389P4CRITICALCVSS 10.0≤ 5.1.1.17v5.1.1+37 more2008-01-23
CVE-2008-0389 [CRITICAL] CVE-2008-0389: Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Applicatio
Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.
nvd
CVE-2023-50315P4MEDIUMCVSS 5.9v8.5.0.0v9.0.0.0+1 more2024-08-14
CVE-2023-50315 [MEDIUM] CWE-295 CVE-2023-50315: IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to c
IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274714.
nvd
CVE-2006-5324P4HIGHCVSS 7.5≤ 6.1.0.12006-10-17
CVE-2006-5324 [HIGH] CVE-2006-5324: The Web Services Notification (WSN) security component of IBM WebSphere Application Server before 6.
The Web Services Notification (WSN) security component of IBM WebSphere Application Server before 6.1.0.2 allows attackers to obtain unspecified access without supplying a username and password, aka PK28374.
nvd
CVE-2010-1182P4HIGHCVSS 7.5v7.0v7.0.0.1+7 more2010-03-29
CVE-2010-1182 [HIGH] CVE-2010-1182: Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Serv
Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknown impact and attack vectors.
nvd