Ibm Websphere Application Server Liberty vulnerabilities
60 known vulnerabilities affecting ibm/websphere_application_server_liberty.
Total CVEs
60
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH29MEDIUM21
Vulnerabilities
Page 1 of 3
CVE-2026-14976P2CRITICALCVSS 9.8≥ 17.0.0.3, ≤ 26.0.0.82026-07-28
CVE-2026-14976 [CRITICAL] CWE-306 CVE-2026-14976: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code exec
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
nvd
CVE-2026-8400P2CRITICALCVSS 9.8vContinuous delivery2026-08-05
CVE-2026-8400 [CRITICAL] CWE-470 CVE-2026-8400: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continu
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
nvd
CVE-2026-14525P3CRITICALCVSS 9.4≥ 17.0.0.3, ≤ 26.0.0.82026-08-13
CVE-2026-14525 [CRITICAL] CWE-306 CVE-2026-14525: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Serve
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
nvd
CVE-2026-8646P3CRITICALCVSS 9.1≥ 17.0.0.3, ≤ 26.0.0.62026-06-22
CVE-2026-8646 [CRITICAL] CWE-444 CVE-2026-8646: IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose
nvd
CVE-2021-39031P3HIGHCVSS 8.8v17.0.0.3v22.0.0.12022-01-25
CVE-2021-39031 [HIGH] CWE-74 CVE-2021-39031: IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authentica
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.
nvd
CVE-2026-14529P3CRITICALCVSS 9.8≥ 17.0.0.3, ≤ 26.0.0.82026-07-29
CVE-2026-14529 [CRITICAL] CWE-306 CVE-2026-14529: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
nvd
CVE-2026-11546P3CRITICALCVSS 9.8≥ 17.0.0.3, ≤ 26.0.0.72026-06-30
CVE-2026-11546 [CRITICAL] CWE-918 CVE-2026-11546: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side re
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
nvd
CVE-2026-11714P3CRITICALCVSS 9.8≥ 17.0.0.3, ≤ 26.0.0.72026-06-30
CVE-2026-11714 [CRITICAL] CWE-918 CVE-2026-11714: IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
nvd
CVE-2026-15325P3HIGHCVSS 8.7≥ 17.0.0.3, ≤ 26.0.0.72026-07-28
CVE-2026-15325 [HIGH] CWE-444 CVE-2026-15325: IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTT
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
nvd
CVE-2026-10842P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.72026-07-30
CVE-2026-10842 [HIGH] CWE-289 CVE-2026-10842: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.
nvd
CVE-2025-14917P3CRITICALCVSS 9.8≥ 17.0.0.3, ≤ 26.0.0.32026-03-25
CVE-2025-14917 [CRITICAL] CWE-1393 CVE-2025-14917: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Serve
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.
nvd
CVE-2026-15064P3HIGHCVSS 8.7≥ 17.0.0.3, ≤ 26.0.0.72026-07-28
CVE-2026-15064 [HIGH] CWE-444 CVE-2026-15064: IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTT
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
nvd
CVE-2026-15280P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.82026-07-28
CVE-2026-15280 [HIGH] CWE-22 CVE-2026-15280: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is aff
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.
nvd
CVE-2025-14923P3CRITICALCVSS 9.8≥ 17.0.0.3, ≤ 26.0.0.22026-03-03
CVE-2025-14923 [CRITICAL] CWE-321 CVE-2025-14923: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Serve
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
nvd
CVE-2026-18499P3HIGHCVSS 8.1≥ 17.0.0.3, ≤ 26.0.0.82026-08-12
CVE-2026-18499 [HIGH] CWE-285 CVE-2026-18499: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege es
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.
nvd
CVE-2026-11806P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.62026-06-30
CVE-2026-11806 [HIGH] CWE-444 CVE-2026-11806: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary fil
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
nvd
CVE-2022-22476P3HIGHCVSS 8.8v17.0.0.3v22.0.0.72022-07-08
CVE-2022-22476 [HIGH] CWE-290 CVE-2022-22476: IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable t
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.
nvd
CVE-2026-15328P3HIGHCVSS 8.1≥ 17.0.0.3, ≤ 26.0.0.72026-07-28
CVE-2026-15328 [HIGH] CWE-444 CVE-2026-15328: IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTT
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling.
nvd
CVE-2026-14980P3HIGHCVSS 8.8≥ 17.0.0.3, ≤ 26.0.0.82026-07-30
CVE-2026-14980 [HIGH] CWE-269 CVE-2026-14980: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site req
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.
nvd
CVE-2024-56339P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 25.0.0.72025-08-07
CVE-2024-56339 [HIGH] CWE-650 CVE-2024-56339: IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.
nvd
1 / 3Next →