VendorsIBMwebsphere_application_serverall versions
Vulnerabilities

IBM WebSphere Application Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

501CVEs
CVE-2018-1904
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.
Published 2018-12-11 · Modified
9.8EPSS 0.037
CVE-2011-4889
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.
Published 2018-02-08 · Modified
9.8EPSS 0.027
CVE-2023-23477
IBM WebSphere Application Server code execution
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2026-14512
IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
Published 2026-07-28 · Analyzed
9.8EPSS 0.010
CVE-2026-8633
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins
Published 2026-05-26 · Analyzed
9.8EPSS 0.009
CVE-2026-14974
IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities
Published 2026-07-28 · Analyzed
9.8EPSS 0.007
CVE-2026-14976
IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability
Published 2026-07-28 · Analyzed
9.8EPSS 0.006
CVE-2026-14529
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery
Published 2026-07-29 · Analyzed
9.8EPSS 0.005
CVE-2026-14446
IBM WebSphere Application Server is affected by a privilege escalation
Published 2026-07-28 · Analyzed
9.8EPSS 0.005
CVE-2026-8400
Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
Published 2026-08-05 · Analyzed
9.8EPSS 0.005
CVE-2026-16184
IBM WebSphere Application Server is affected by an authentication bypass
Published 2026-07-28 · Analyzed
9.8EPSS 0.005
CVE-2026-11541
Inconsistent Interpretation of HTTP Requests in CICS Transaction Gateway for Multiplatforms.
Published 2026-06-30 · Modified
9.8EPSS 0.004
CVE-2025-14917
IBM WebSphere Application Server Liberty could provide weaker than expected security
Published 2026-03-25 · Analyzed
9.8EPSS 0.004
CVE-2026-11546
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability
Published 2026-06-30 · Analyzed
9.8EPSS 0.004
CVE-2026-11714
IBM WebSphere Application Server Liberty is affected by an authorization bypass vulnerability
Published 2026-06-30 · Modified
9.8EPSS 0.004
CVE-2025-14923
IBM WebSphere Application Server Liberty could provide weaker than expected security
Published 2026-03-03 · Analyzed
9.8EPSS 0.002
CVE-2026-14525
IBM WebSphere Application Server Liberty is affected by an authenication bypass
Published 2026-08-13 · Analyzed
9.4EPSS 0.006
CVE-2015-1885
WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attackers to gain privileges via unspecified vectors.
Published 2015-04-26 · Modified
9.3EPSS 0.034
CVE-2008-4111
Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when the FileServing feature is enabled, has unknown impact and attack vectors.
Published 2008-09-16 · Modified
9.3EPSS 0.023
CVE-2007-3960
Multiple unspecified vulnerabilities in IBM WebSphere Application Server (WAS) before Fix Pack 21 (6.0.2.21) have unknown impact and attack vectors, aka (1) PK33799, or (2) a "Potential security exposure" in the Samples component (PK40213).
Published 2007-07-24 · Modified
9.3EPSS 0.019
CVE-2026-11708
IBM WebSphere Application Server is affected by a cross-site scripting vulnerability
Published 2026-06-30 · Analyzed
9.3EPSS 0.004
CVE-2026-11707
Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
Published 2026-07-30 · Analyzed
9.3EPSS 0.004
CVE-2026-11712
IBM WebSphere Application Server is affected by a cross-site scripting vulnerability
Published 2026-06-30 · Analyzed
9.3EPSS 0.004
CVE-2015-5041
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.
Published 2016-06-06 · Modified
9.1EPSS 0.039
CVE-2023-27554
IBM WebSphere Application Server XML external entity injection
Published 2023-05-11 · Modified
9.1EPSS 0.009
CVE-2026-8646
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-06-22 · Analyzed
9.1EPSS 0.006
CVE-2026-8644
IBM WebSphere Application Server is affected by an identity spoofing vulnerability
Published 2026-06-01 · Analyzed
9.1EPSS 0.005
CVE-2026-9006
IBM WebSphere Application Server is affected by server-side request forgery
Published 2026-06-22 · Analyzed
9.1EPSS 0.004
CVE-2020-4464
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.
Published 2020-07-17 · Modified
9.0EPSS 0.132
CVE-2026-9311
IBM WebSphere Application Server is affected by remote code execution
Published 2026-06-01 · Analyzed
9.0EPSS 0.006
CVE-2026-9319
IBM WebSphere Application Server is affected by a remote code execution vulnerability
Published 2026-06-01 · Analyzed
9.0EPSS 0.006
CVE-2017-1731
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.
Published 2018-01-30 · Modified
8.8EPSS 0.028
CVE-2020-4362
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.
Published 2020-04-10 · Modified
8.8EPSS 0.024
CVE-2021-39031
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.
Published 2022-01-25 · Modified
8.8EPSS 0.020
CVE-2018-1901
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.
Published 2018-12-12 · Modified
8.8EPSS 0.015
CVE-2018-1926
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious URL, a remote attacker could send a specially-crafted request. An attacker could exploit this vulnerability to perform CSRF attack and update available applications. IBM X-Force ID: 152992.
Published 2018-12-12 · Modified
8.8EPSS 0.012
CVE-2021-29736
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.
Published 2021-07-30 · Modified
8.8EPSS 0.011
CVE-2017-1194
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.
Published 2017-04-28 · Modified
8.8EPSS 0.009
CVE-2022-22476
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.
Published 2022-07-08 · Modified
8.8EPSS 0.009
CVE-2021-29754
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
Published 2021-06-11 · Modified
8.8EPSS 0.007
← Prev2 / 13Next →