VendorsIBMwebsphere_application_serverany version
Vulnerabilities

IBM WebSphere Application Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

237CVEs
CVE-2018-1553
IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature. IBM X-Force ID: 142890.
Published 2018-06-27 · Modified
7.5EPSS 0.029
CVE-2020-4643
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
Published 2020-09-21 · Modified
7.5EPSS 0.028
CVE-2019-4269
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console could allow a remote attacker to obtain sensitive information when a specially crafted url causes a stack trace to be dumped. IBM X-Force ID: 160202.
Published 2019-06-28 · Modified
7.5EPSS 0.027
CVE-2020-4576
IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 184428.
Published 2020-10-01 · Modified
7.5EPSS 0.020
CVE-2018-1683
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455.
Published 2018-09-26 · Modified
7.5EPSS 0.020
CVE-2019-4720
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available memory. IBM X-Force ID: 172125.
Published 2020-01-31 · Modified
7.5EPSS 0.018
CVE-2006-5324
The Web Services Notification (WSN) security component of IBM WebSphere Application Server before 6.1.0.2 allows attackers to obtain unspecified access without supplying a username and password, aka PK28374.
Published 2006-10-17 · Modified
7.5EPSS 0.018
CVE-2007-1608
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.
Published 2007-03-22 · Modified
7.5EPSS 0.017
CVE-2001-0962
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
Published 2002-06-25 · Modified
7.5EPSS 0.016
CVE-2006-4136
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadIdentitySupport, and possibly others.
Published 2006-08-14 · Modified
7.5EPSS 0.015
CVE-2007-1945
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
Published 2007-04-11 · Modified
7.5EPSS 0.014
CVE-2024-27268
IBM WebSphere Application Server Liberty denial of service
Published 2024-04-04 · Analyzed
7.5EPSS 0.013
CVE-2011-1309
The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.
Published 2011-03-08 · Modified
7.5EPSS 0.012
CVE-2010-2324
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows attackers to perform unspecified "link injection" actions via unknown vectors.
Published 2010-06-18 · Modified
7.5EPSS 0.012
CVE-2023-38737
IBM WebSphere Application Server Liberty denial of service
Published 2023-08-16 · Modified
7.5EPSS 0.010
CVE-2024-22353
IBM WebSphere Application Server Liberty denial of service
Published 2024-03-31 · Modified
7.5EPSS 0.008
CVE-2024-25026
IBM WebSphere Application Server denial of service
Published 2024-04-25 · Analyzed
7.5EPSS 0.008
CVE-2026-11595
IBM WebSphere Application Server is affected by a Path Traversal vulnerability
Published 2026-06-30 · Analyzed
7.5EPSS 0.008
CVE-2026-9336
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
Published 2026-09-10 · Analyzed
7.5EPSS 0.008
CVE-2026-4410
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a denial of service
Published 2026-05-27 · Analyzed
7.5EPSS 0.007
CVE-2026-9071
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by Uncontrolled Resource Consumption
Published 2026-06-22 · Analyzed
7.5EPSS 0.006
CVE-2023-30441
IBM Java information disclosure
Published 2023-04-29 · Modified
7.5EPSS 0.006
CVE-2024-45085
IBM WebSphere Application Server denial of service
Published 2024-10-15 · Analyzed
7.5EPSS 0.006
CVE-2026-9320
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-06-22 · Analyzed
7.5EPSS 0.006
CVE-2026-9322
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-07-30 · Analyzed
7.5EPSS 0.006
CVE-2026-11897
IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability with HTTP/2
Published 2026-07-30 · Analyzed
7.5EPSS 0.005
CVE-2026-10842
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability
Published 2026-07-30 · Analyzed
7.5EPSS 0.005
CVE-2026-15280
IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability
Published 2026-07-28 · Analyzed
7.5EPSS 0.005
CVE-2026-11806
IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerability
Published 2026-06-30 · Analyzed
7.5EPSS 0.005
CVE-2026-14981
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-07-28 · Modified
7.5EPSS 0.005
CVE-2026-15057
IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability
Published 2026-07-28 · Analyzed
7.5EPSS 0.005
CVE-2026-14528
IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
Published 2026-07-28 · Analyzed
7.5EPSS 0.005
CVE-2025-36047
IBM WebSphere Application Server Liberty denial of service
Published 2025-08-14 · Modified
7.5EPSS 0.005
CVE-2024-56339
IBM WebSphere Application Server information disclosure
Published 2025-08-07 · Analyzed
7.5EPSS 0.004
CVE-2025-36097
IBM WebSphere Application Server denial of service
Published 2025-07-16 · Analyzed
7.5EPSS 0.004
CVE-2025-36124
IBM WebSphere Application Server Liberty bypass security
Published 2025-08-12 · Analyzed
7.5EPSS 0.004
CVE-2026-8620
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins
Published 2026-05-26 · Analyzed
7.5EPSS 0.004
CVE-2026-3621
IBM WebSphere Application Server Liberty is affected by identity spoofing
Published 2026-04-22 · Analyzed
7.5EPSS 0.004
CVE-2025-33142
IBM WebSphere Application Server information disclosure
Published 2025-08-14 · Analyzed
7.5EPSS 0.003
CVE-2023-50314
IBM WebSphere Application Server Libery information disclosure
Published 2024-08-14 · Analyzed
7.5EPSS 0.003
← Prev3 / 6Next →