VendorsIBMwebsphere_application_serverany version
Vulnerabilities

IBM WebSphere Application Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

237CVEs
CVE-2026-10845
IBM WebSphere Application Server is affected by an authentication bypass vulnerability
Published 2026-06-22 · Analyzed
7.3EPSS 0.005
CVE-2020-4163
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397.
Published 2020-02-04 · Modified
7.2EPSS 0.016
CVE-2024-35154
IBM WebSphere Application Server code execution
Published 2024-07-09 · Modified
7.2EPSS 0.012
CVE-2025-14915
IBM WebSphere Application Server Liberty is affected by a privilege escalation vulnerability
Published 2026-03-25 · Analyzed
7.2EPSS 0.006
CVE-2018-1905
IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152534.
Published 2018-11-26 · Modified
7.1EPSS 0.025
CVE-2026-16192
IBM WebSphere Application Server Liberty is affected by a denial of service
Published 2026-07-28 · Analyzed
7.1EPSS 0.004
CVE-2017-1382
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.
Published 2017-07-24 · Modified
7.1EPSS 0.004
CVE-2026-9176
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
Published 2026-09-10 · Analyzed
7.1EPSS 0.002
CVE-2024-22354
IBM WebSphere Application Server XML external entity injection
Published 2024-04-17 · Analyzed
7.0EPSS 0.006
CVE-2019-4080
IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter parsing. A remote attacker could exploit this to consume all available CPU resources. IBM X-Force ID: 157380.
Published 2019-04-02 · Modified
6.8EPSS 0.031
CVE-2010-3271
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.
Published 2011-07-18 · Modified
6.81 PoCEPSS 0.021
CVE-2012-2162
The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.
Published 2012-05-01 · Modified
6.8EPSS 0.012
CVE-2018-1770
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148686.
Published 2018-10-12 · Modified
6.5EPSS 0.035
CVE-2020-4782
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Published 2020-10-28 · Modified
6.5EPSS 0.026
CVE-2020-5016
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. When application security is disabled and JAX-RPC applications are present, an attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary xml files on the system. This does not occur if Application security is enabled. IBM X-Force ID: 193556.
Published 2021-03-10 · Modified
6.5EPSS 0.023
CVE-2019-4670
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper data representation. IBM X-Force ID: 171319.
Published 2020-02-05 · Modified
6.5EPSS 0.018
CVE-2018-1838
IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords. IBM X-Force ID: 150811.
Published 2018-10-12 · Modified
6.5EPSS 0.016
CVE-2019-4477
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive information, caused by improper handling of command line options. IBM X-Force ID: 163997.
Published 2019-09-17 · Modified
6.5EPSS 0.013
CVE-2020-4590
IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.
Published 2020-09-21 · Modified
6.5EPSS 0.012
CVE-2021-20480
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197502.
Published 2021-04-08 · Modified
6.5EPSS 0.012
CVE-2022-22310
IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 217224.
Published 2022-01-19 · Modified
6.5EPSS 0.010
CVE-2019-4304
IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950.
Published 2019-09-30 · Modified
6.5EPSS 0.010
CVE-2022-22393
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could allow an authenticated user to issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server. IBM X-Force ID: 222078.
Published 2022-05-13 · Modified
6.5EPSS 0.007
CVE-2022-22475
IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM X-Force ID: 225603.
Published 2022-05-17 · Modified
6.5EPSS 0.006
CVE-2023-50312
IBM WebSphere Application Server Liberty information disclosure
Published 2024-03-01 · Analyzed
6.5EPSS 0.006
CVE-2022-35282
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker with local network access could exploit this vulnerability to obtain sensitive data.
Published 2022-09-28 · Modified
6.5EPSS 0.003
CVE-2018-1797
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using Enterprise bundle Archives (EBA) could allow a local attacker to traverse directories on the system. By persuading a victim to extract a specially-crafted ZIP archive containing "dot dot slash" sequences (../), an attacker could exploit this vulnerability to write to arbitrary files on the system. Note: This vulnerability is known as "Zip-Slip". IBM X-Force ID: 149427.
Published 2018-11-16 · Modified
6.3EPSS 0.020
CVE-2018-1643
The Installation Verification Tool of IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144588
Published 2018-11-15 · Modified
6.1EPSS 0.015
CVE-2018-1798
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 149428.
Published 2018-11-12 · Modified
6.1EPSS 0.015
CVE-2018-1767
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148621.
Published 2018-10-29 · Modified
6.1EPSS 0.014
CVE-2018-1794
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148949.
Published 2018-10-03 · Modified
6.1EPSS 0.014
CVE-2020-4575
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
Published 2020-08-27 · Modified
6.1EPSS 0.009
CVE-2020-4303
IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176668.
Published 2020-04-02 · Modified
6.1EPSS 0.008
CVE-2020-4304
IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176670.
Published 2020-04-02 · Modified
6.1EPSS 0.008
CVE-2023-24966
IBM WebSphere Application Server cross-site scripting
Published 2023-04-27 · Modified
6.1EPSS 0.004
CVE-2024-27270
IBM WebSphere Application Server Liberty cross-site scripting
Published 2024-03-27 · Analyzed
6.1EPSS 0.004
CVE-2026-14515
IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities
Published 2026-07-28 · Analyzed
6.1EPSS 0.003
CVE-2011-1311
The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.xmi file, which might allow remote authenticated users to gain privileges in opportunistic circumstances by requesting a service.
Published 2011-03-08 · Modified
6.0EPSS 0.009
CVE-2018-1755
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC). This can happen when the Application Server is configured to permit access on non-secure (http) port and using JASPIC or JSR375 authentication.
Published 2018-08-24 · Modified
5.9EPSS 0.035
CVE-2018-1719
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This could result in a downgrade of TLS protocol. A remote attacker could exploit this vulnerability to perform man-in-the-middle attacks. IBM X-Force ID: 147292.
Published 2018-09-14 · Modified
5.9EPSS 0.024
← Prev4 / 6Next →