cbcvebase.

Ibm Websphere Application Server Liberty vulnerabilities

43 known vulnerabilities affecting ibm/websphere_application_server_liberty.

Total CVEs
43
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH17MEDIUM19

Vulnerabilities

Page 1 of 3
CVE-2021-39031P3HIGHCVSS 8.8v17.0.0.3v22.0.0.12022-01-25
CVE-2021-39031 [HIGH] CWE-74 CVE-2021-39031: IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authentica IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.
nvd
CVE-2026-11541P3CRITICALCVSS 9.8≥ 17.0.0.3, ≤ 26.0.0.62026-06-30
CVE-2026-11541 [CRITICAL] CWE-444 CVE-2026-11541: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0. IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
nvd
CVE-2026-8646P3CRITICALCVSS 9.1≥ 17.0.0.3, ≤ 26.0.0.62026-06-22
CVE-2026-8646 [CRITICAL] CWE-444 CVE-2026-8646: IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose
nvd
CVE-2026-11546P3CRITICALCVSS 9.8≥ 17.0.0.3, ≤ 26.0.0.72026-06-30
CVE-2026-11546 [CRITICAL] CWE-918 CVE-2026-11546: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side re IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
nvd
CVE-2026-11714P3CRITICALCVSS 9.8≥ 17.0.0.3, ≤ 26.0.0.72026-06-30
CVE-2026-11714 [CRITICAL] CWE-918 CVE-2026-11714: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side re IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
nvd
CVE-2025-14917P3CRITICALCVSS 9.8≥ 17.0.0.3, ≤ 26.0.0.32026-03-25
CVE-2025-14917 [CRITICAL] CWE-1393 CVE-2025-14917: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Serve IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.
nvd
CVE-2025-14923P3CRITICALCVSS 9.8≥ 17.0.0.3, ≤ 26.0.0.22026-03-03
CVE-2025-14923 [CRITICAL] CWE-321 CVE-2025-14923: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Serve IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
nvd
CVE-2022-22476P3HIGHCVSS 8.8v17.0.0.3v22.0.0.72022-07-08
CVE-2022-22476 [HIGH] CWE-290 CVE-2022-22476: IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable t IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.
nvd
CVE-2026-11806P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.62026-06-30
CVE-2026-11806 [HIGH] CWE-444 CVE-2026-11806: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary fil IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
nvd
CVE-2024-56339P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 25.0.0.72025-08-07
CVE-2024-56339 [HIGH] CWE-650 CVE-2024-56339: IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0. IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.
nvd
CVE-2023-46158P3CRITICALCVSS 9.8≥ 23.0.0.9, < 23.0.0.11v23.0.0.9, 23.0.0.102023-10-25
CVE-2023-46158 [CRITICAL] CWE-613 CVE-2023-46158: IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expect IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.
nvd
CVE-2025-36124P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 25.0.0.82025-08-12
CVE-2025-36124 [HIGH] CWE-268 CVE-2025-36124: IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration
nvd
CVE-2026-9071P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.62026-06-22
CVE-2026-9071 [HIGH] CWE-400 CVE-2026-9071: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0. IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2026-4410P3HIGHCVSS 7.5≥ 19.0.0.7, ≤ 26.0.0.52026-05-27
CVE-2026-4410 [HIGH] CWE-400 CVE-2026-4410: IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application S IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2025-14915P3HIGHCVSS 7.2≥ 17.0.0.3, ≤ 26.0.0.32026-03-25
CVE-2025-14915 [HIGH] CWE-200 CVE-2025-14915: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Serve IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.
nvd
CVE-2025-14914P3HIGHCVSS 7.6≥ 17.0.0.3, ≤ 26.0.0.12026-02-02
CVE-2025-14914 [HIGH] CWE-22 CVE-2025-14914: IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.
nvd
CVE-2024-22354P3HIGHCVSS 7.0≥ 17.0.0.3, ≤ 24.0.0.5vcpe:2.3:a:ibm:websphere_application_server:17.0.0.3:*:*:*:liberty:*:*:*+1 more2024-04-17
CVE-2024-22354 [HIGH] CWE-611 CVE-2024-22354: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forg
nvd
CVE-2024-27268P3HIGHCVSS 7.5≥ 18.0.0.2, ≤ 24.0.0.42024-04-04
CVE-2024-27268 [HIGH] CWE-770 CVE-2024-27268: IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of serv IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 284574.
nvd
CVE-2024-25026P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 24.0.0.42024-04-25
CVE-2024-25026 [HIGH] CWE-770 CVE-2024-25026: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 281516.
nvd
CVE-2026-9320P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.62026-06-22
CVE-2026-9320 [HIGH] CWE-400 CVE-2026-9320: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0. IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
Ibm Websphere Application Server Liberty vulnerabilities | cvebase