Ibm Websphere Application Server Liberty vulnerabilities
60 known vulnerabilities affecting ibm/websphere_application_server_liberty.
Total CVEs
60
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH29MEDIUM21
Vulnerabilities
Page 2 of 3
CVE-2026-2482P3HIGHCVSS 8.8≥ 17.0.0.3, ≤ 26.0.0.82026-07-29
CVE-2026-2482 [HIGH] CWE-352 CVE-2026-2482: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site req
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2023-46158P3CRITICALCVSS 9.8≥ 23.0.0.9, < 23.0.0.11v23.0.0.9, 23.0.0.102023-10-25
CVE-2023-46158 [CRITICAL] CWE-613 CVE-2023-46158: IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expect
IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.
nvd
CVE-2025-14915P3HIGHCVSS 7.2≥ 17.0.0.3, ≤ 26.0.0.32026-03-25
CVE-2025-14915 [HIGH] CWE-200 CVE-2025-14915: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Serve
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.
nvd
CVE-2026-4410P3HIGHCVSS 7.5≥ 19.0.0.7, ≤ 26.0.0.52026-05-27
CVE-2026-4410 [HIGH] CWE-400 CVE-2026-4410: IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application S
IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2026-9071P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.62026-06-22
CVE-2026-9071 [HIGH] CWE-400 CVE-2026-9071: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2025-36124P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 25.0.0.82025-08-12
CVE-2025-36124 [HIGH] CWE-268 CVE-2025-36124: IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration
nvd
CVE-2025-14914P3HIGHCVSS 7.6≥ 17.0.0.3, ≤ 26.0.0.12026-02-02
CVE-2025-14914 [HIGH] CWE-22 CVE-2025-14914: IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.
nvd
CVE-2026-9320P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.62026-06-22
CVE-2026-9320 [HIGH] CWE-400 CVE-2026-9320: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2026-11897P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.72026-07-30
CVE-2026-11897 [HIGH] CWE-770 CVE-2026-11897: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of se
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2024-27268P3HIGHCVSS 7.5≥ 18.0.0.2, ≤ 24.0.0.42024-04-04
CVE-2024-27268 [HIGH] CWE-770 CVE-2024-27268: IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of serv
IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 284574.
nvd
CVE-2024-25026P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 24.0.0.42024-04-25
CVE-2024-25026 [HIGH] CWE-770 CVE-2024-25026: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 281516.
nvd
CVE-2024-22354P3HIGHCVSS 7.0≥ 17.0.0.3, ≤ 24.0.0.5vcpe:2.3:a:ibm:websphere_application_server:17.0.0.3:*:*:*:liberty:*:*:*+1 more2024-04-17
CVE-2024-22354 [HIGH] CWE-611 CVE-2024-22354: IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 thro
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forg
nvd
CVE-2024-22353P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 24.0.0.42024-03-31
CVE-2024-22353 [HIGH] CWE-770 CVE-2024-22353: IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of serv
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 280400.
nvd
CVE-2026-9322P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.72026-07-30
CVE-2026-9322 [HIGH] CWE-400 CVE-2026-9322: IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
nvd
CVE-2025-36047P3HIGHCVSS 7.5≥ 18.0.0.2, ≤ 25.0.0.82025-08-14
CVE-2025-36047 [HIGH] CWE-770 CVE-2025-36047: IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of serv
IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
nvd
CVE-2023-38737P3HIGHCVSS 7.5≥ 22.0.0.13, ≤ 23.0.0.72023-08-16
CVE-2023-38737 [HIGH] CWE-20 CVE-2023-38737: IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of ser
IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 262567.
nvd
CVE-2026-15057P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.72026-07-28
CVE-2026-15057 [HIGH] CWE-787 CVE-2026-15057: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of se
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
nvd
CVE-2026-14981P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 26.0.0.72026-07-28
CVE-2026-14981 [HIGH] CWE-400 CVE-2026-14981: IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a de
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
nvd
CVE-2025-36097P3HIGHCVSS 7.5≥ 17.0.0.3, ≤ 25.0.0.72025-07-16
CVE-2025-36097 [HIGH] CWE-121 CVE-2025-36097: IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
nvd
CVE-2026-5516P3MEDIUMCVSS 5.9≥ 22.0.0.11, ≤ 26.0.0.52026-05-27
CVE-2026-5516 [MEDIUM] CWE-362 CVE-2026-5516: IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Serv
IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.
nvd