VendorsIBMwebsphere_application_serverall versions
Vulnerabilities

IBM WebSphere Application Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

501CVEs
CVE-2026-9322
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-07-30 · Analyzed
7.5EPSS 0.006
CVE-2026-11897
IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability with HTTP/2
Published 2026-07-30 · Analyzed
7.5EPSS 0.005
CVE-2022-43917
IBM WebSphere Application Server information disclosure
Published 2023-01-25 · Modified
7.5EPSS 0.005
CVE-2026-10842
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability
Published 2026-07-30 · Analyzed
7.5EPSS 0.005
CVE-2026-15280
IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability
Published 2026-07-28 · Analyzed
7.5EPSS 0.005
CVE-2026-11806
IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerability
Published 2026-06-30 · Analyzed
7.5EPSS 0.005
CVE-2026-15057
IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability
Published 2026-07-28 · Analyzed
7.5EPSS 0.005
CVE-2026-14981
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-07-28 · Modified
7.5EPSS 0.005
CVE-2026-14528
IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
Published 2026-07-28 · Analyzed
7.5EPSS 0.005
CVE-2025-36047
IBM WebSphere Application Server Liberty denial of service
Published 2025-08-14 · Modified
7.5EPSS 0.005
CVE-2024-56339
IBM WebSphere Application Server information disclosure
Published 2025-08-07 · Analyzed
7.5EPSS 0.004
CVE-2025-36097
IBM WebSphere Application Server denial of service
Published 2025-07-16 · Analyzed
7.5EPSS 0.004
CVE-2025-36124
IBM WebSphere Application Server Liberty bypass security
Published 2025-08-12 · Analyzed
7.5EPSS 0.004
CVE-2026-8620
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins
Published 2026-05-26 · Analyzed
7.5EPSS 0.004
CVE-2026-3621
IBM WebSphere Application Server Liberty is affected by identity spoofing
Published 2026-04-22 · Analyzed
7.5EPSS 0.004
CVE-2025-33142
IBM WebSphere Application Server information disclosure
Published 2025-08-14 · Analyzed
7.5EPSS 0.003
CVE-2023-50314
IBM WebSphere Application Server Libery information disclosure
Published 2024-08-14 · Analyzed
7.5EPSS 0.003
CVE-2018-1695
IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769.
Published 2018-09-06 · Modified
7.3EPSS 0.022
CVE-2026-10845
IBM WebSphere Application Server is affected by an authentication bypass vulnerability
Published 2026-06-22 · Analyzed
7.3EPSS 0.005
CVE-2020-4163
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397.
Published 2020-02-04 · Modified
7.2EPSS 0.016
CVE-2024-35154
IBM WebSphere Application Server code execution
Published 2024-07-09 · Modified
7.2EPSS 0.012
CVE-2019-4732
IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 172618.
Published 2020-02-03 · Modified
7.2EPSS 0.006
CVE-2025-14915
IBM WebSphere Application Server Liberty is affected by a privilege escalation vulnerability
Published 2026-03-25 · Analyzed
7.2EPSS 0.006
CVE-2009-0436
The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS), set incorrect permissions for AF_UNIX sockets, which has unknown impact and local attack vectors.
Published 2009-02-10 · Modified
7.2EPSS 0.004
CVE-1999-0852
IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.
Published 2000-02-04 · Modified
7.2EPSS 0.003
CVE-2014-0964
IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.
Published 2014-05-16 · Modified
7.1EPSS 0.027
CVE-2018-1905
IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152534.
Published 2018-11-26 · Modified
7.1EPSS 0.025
CVE-2014-4764
IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial of service (Load Balancer crash) via unspecified vectors.
Published 2014-08-22 · Modified
7.1EPSS 0.024
CVE-2026-16192
IBM WebSphere Application Server Liberty is affected by a denial of service
Published 2026-07-28 · Analyzed
7.1EPSS 0.004
CVE-2017-1382
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.
Published 2017-07-24 · Modified
7.1EPSS 0.004
CVE-2026-9176
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
Published 2026-09-10 · Analyzed
7.1EPSS 0.002
CVE-2024-22354
IBM WebSphere Application Server XML external entity injection
Published 2024-04-17 · Analyzed
7.0EPSS 0.006
CVE-2019-4080
IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, caused by improper parameter parsing. A remote attacker could exploit this to consume all available CPU resources. IBM X-Force ID: 157380.
Published 2019-04-02 · Modified
6.8EPSS 0.031
CVE-2013-0543
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
Published 2013-04-24 · Modified
6.8EPSS 0.025
CVE-2015-1927
The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors.
Published 2015-07-14 · Modified
6.8EPSS 0.021
CVE-2010-3271
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.
Published 2011-07-18 · Modified
6.81 PoCEPSS 0.021
CVE-2012-3304
The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors.
Published 2012-09-25 · Modified
6.8EPSS 0.021
CVE-2011-1683
IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registry or Federated Repository with RACF adapter is used, allows remote attackers to obtain unspecified application access via unknown vectors.
Published 2011-04-13 · Modified
6.8EPSS 0.017
CVE-2012-3306
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified impact and remote attack vectors.
Published 2012-09-25 · Modified
6.8EPSS 0.016
CVE-2008-4679
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate.
Published 2008-10-22 · Modified
6.8EPSS 0.016
← Prev5 / 13Next →