VendorsIBMwebsphere_application_serverall versions
Vulnerabilities

IBM WebSphere Application Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

501CVEs
CVE-2026-14980
IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
Published 2026-07-30 · Analyzed
8.8EPSS 0.004
CVE-2020-4534
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this vulnerability to execute arbitrary code with higher privileges. IBM X-Force ID: 182808.
Published 2020-08-03 · Modified
8.8EPSS 0.004
CVE-2024-37532
IBM WebSphere Application Server identity spoofing
Published 2024-06-20 · Modified
8.8EPSS 0.004
CVE-2026-2482
IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
Published 2026-07-29 · Analyzed
8.8EPSS 0.002
CVE-2026-15064
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-07-28 · Modified
8.7EPSS 0.003
CVE-2026-15325
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-07-28 · Modified
8.7EPSS 0.003
CVE-2015-1882
Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.
Published 2015-04-26 · Modified
8.5EPSS 0.030
CVE-2026-9330
IBM WebSphere Application Server is affected by remote code execution
Published 2026-06-01 · Analyzed
8.5EPSS 0.007
CVE-2026-11536
IBM WebSphere Application Server is affected by a remote code execution vulnerability
Published 2026-07-30 · Analyzed
8.5EPSS 0.006
CVE-2026-11594
IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities
Published 2026-06-30 · Analyzed
8.5EPSS 0.003
CVE-2021-20353
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.
Published 2021-02-10 · Modified
8.2EPSS 0.052
CVE-2020-4949
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
Published 2021-01-26 · Modified
8.2EPSS 0.048
CVE-2021-20454
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.
Published 2021-04-21 · Modified
8.2EPSS 0.028
CVE-2021-20453
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648.
Published 2021-04-20 · Modified
8.2EPSS 0.025
CVE-2021-20492
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.
Published 2021-05-26 · Modified
8.2EPSS 0.021
CVE-2017-1151
IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could allow a user to gain elevated privileges on the system. IBM Reference #: 1999293.
Published 2017-03-20 · Modified
8.1EPSS 0.022
CVE-2018-1840
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.
Published 2018-12-03 · Modified
8.1EPSS 0.021
CVE-2017-1137
IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549.
Published 2017-05-10 · Modified
8.1EPSS 0.019
CVE-2026-18499
IBM WebSphere Application Server Liberty is affected by a privilege escalation
Published 2026-08-12 · Analyzed
8.1EPSS 0.004
CVE-2026-15328
IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent Interpretation of HTTP Requests
Published 2026-07-28 · Modified
8.1EPSS 0.004
CVE-2026-9327
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
Published 2026-09-10 · Analyzed
8.1EPSS 0.004
CVE-2021-20354
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
Published 2021-02-18 · Modified
7.8EPSS 0.041
CVE-2007-3262
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a "TCP issue," or to MPAlarmThread and a resultant memory leak.
Published 2007-06-19 · Modified
7.8EPSS 0.029
CVE-2016-8919
IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and cause the consumption of resources.
Published 2017-02-01 · Modified
7.8EPSS 0.028
CVE-2009-2744
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unknown vectors, related to "an error in fixpacks 6.1.0.23 and 6.1.0.25."
Published 2009-09-21 · Modified
7.8EPSS 0.025
CVE-2008-4678
The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."
Published 2008-10-22 · Modified
7.8EPSS 0.019
CVE-2005-3760
Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allows attackers to cause a denial of service (ABEND).
Published 2005-11-22 · Modified
7.8EPSS 0.015
CVE-2009-0391
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.
Published 2009-02-02 · Modified
7.8EPSS 0.014
CVE-2013-3024
IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initialization. IBM X-Force ID: 84362.
Published 2018-05-24 · Modified
7.8EPSS 0.004
CVE-2025-14914
IBM WebSphere Application Server Liberty Path Traversal
Published 2026-02-02 · Analyzed
7.6EPSS 0.004
CVE-2025-33104
IBM WebSphere Application Server cross
Published 2025-05-14 · Analyzed
7.6EPSS 0.002
CVE-2010-1632
Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.
Published 2010-06-22 · Modified
7.5EPSS 0.224
CVE-2016-5983
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.
Published 2016-10-05 · Modified
7.5EPSS 0.041
CVE-2020-4449
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181230.
Published 2020-06-05 · Modified
7.5EPSS 0.039
CVE-2019-4046
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handling of request headers. A remote attacker could exploit this vulnerability to cause the consumption of Memory. IBM X-Force ID: 156242.
Published 2019-03-25 · Modified
7.5EPSS 0.032
CVE-2005-1872
Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.
Published 2005-06-07 · Modified
7.5EPSS 0.032
CVE-2020-4276
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.
Published 2020-03-26 · Modified
7.5EPSS 0.031
CVE-2000-0497
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
Published 2000-10-13 · Modified
7.5EPSS 0.031
CVE-2009-0508
The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console.
Published 2009-03-16 · Modified
7.5EPSS 0.029
CVE-2018-1553
IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature. IBM X-Force ID: 142890.
Published 2018-06-27 · Modified
7.5EPSS 0.029
← Prev3 / 13Next →