VendorsIBMwebsphere_application_serverany version
Vulnerabilities

IBM WebSphere Application Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

237CVEs
CVE-2022-22365
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, is vulnerable to spoofing by allowing a man-in-the-middle attacker to spoof SSL server hostnames. IBM X-Force ID: 220904.
Published 2022-05-20 · Modified
5.9EPSS 0.006
CVE-2022-38712
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762."
Published 2022-11-03 · Modified
5.9EPSS 0.005
CVE-2026-5516
IBM WebSphere Application Server Liberty is affected by a security bypass vulnerability
Published 2026-05-27 · Modified
5.9EPSS 0.003
CVE-2026-10571
IBM WebSphere Application Server Liberty is affected by a denial of service
Published 2026-08-13 · Analyzed
5.7EPSS 0.006
CVE-2020-4421
IBM WebSphere Application Liberty 19.0.0.5 through 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.
Published 2020-05-06 · Modified
5.5EPSS 0.006
CVE-2024-45072
IBM WebSphere Application Server XML external entity injection
Published 2024-10-16 · Analyzed
5.5EPSS 0.004
CVE-2024-45086
IBM WebSphere Application Server XML external entity injection
Published 2024-11-04 · Analyzed
5.5EPSS 0.004
CVE-2018-1957
IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629.
Published 2018-12-10 · Modified
5.5EPSS 0.004
CVE-2024-45071
IBM WebSphere Application Server cross-site scripting
Published 2024-10-16 · Analyzed
5.5EPSS 0.002
CVE-2016-3042
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving OpenID Connect clients.
Published 2016-10-01 · Modified
5.4EPSS 0.011
CVE-2019-4285
IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a specially-crafted HTTP request to hijack the victim's click actions or launch other client-side browser attacks. IBM X-Force ID: 160513.
Published 2019-07-30 · Modified
5.4EPSS 0.011
CVE-2017-1380
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127151.
Published 2017-07-24 · Modified
5.4EPSS 0.010
CVE-2018-1777
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148800.
Published 2018-10-16 · Modified
5.4EPSS 0.010
CVE-2019-4270
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160203.
Published 2019-09-17 · Modified
5.4EPSS 0.007
CVE-2020-4578
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.
Published 2020-09-10 · Modified
5.4EPSS 0.007
CVE-2019-4030
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155946.
Published 2019-03-06 · Modified
5.4EPSS 0.007
CVE-2019-4663
IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171245.
Published 2019-12-10 · Modified
5.4EPSS 0.006
CVE-2021-39038
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 213968.
Published 2022-02-24 · Modified
5.4EPSS 0.006
CVE-2022-34165
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and cross-site scripting. IBM X-Force ID: 229429.
Published 2022-09-09 · Modified
5.4EPSS 0.006
CVE-2026-1561
IBM WebSphere Application Server Liberty Server-Side Request Forgery
Published 2026-03-25 · Analyzed
5.4EPSS 0.003
CVE-2026-11383
Cross-site Scripting in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
Published 2026-07-30 · Analyzed
5.4EPSS 0.002
CVE-2025-12635
IBM WebSphere Application Server and WebSphere Application Server Liberty Cross-Site Scripting
Published 2025-12-08 · Analyzed
5.4EPSS 0.002
CVE-2019-4268
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 160201.
Published 2019-09-17 · Modified
5.3EPSS 0.027
CVE-2019-4505
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL. This can lead the attacker to view any file in a certain directory. IBM X-Force ID: 164364.
Published 2019-09-20 · Modified
5.3EPSS 0.024
CVE-2020-10693
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
Published 2020-05-06 · Modified
5.3EPSS 0.024
CVE-2017-1788
IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 137031.
Published 2018-03-22 · Modified
5.3EPSS 0.023
CVE-2019-4441
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.
Published 2019-10-03 · Modified
5.3EPSS 0.016
CVE-2019-4305
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the improper setting of a cookie. IBM X-Force ID: 160951.
Published 2019-09-30 · Modified
5.3EPSS 0.015
CVE-2020-4365
IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.
Published 2020-05-14 · Modified
5.3EPSS 0.014
CVE-2021-29842
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.
Published 2021-09-16 · Modified
5.3EPSS 0.013
CVE-2018-1996
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the improper TLS configuration. A remote attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 154650.
Published 2019-02-19 · Modified
5.3EPSS 0.011
CVE-2022-22473
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force ID: 225347.
Published 2022-07-14 · Modified
5.3EPSS 0.011
CVE-2026-9338
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
Published 2026-09-10 · Analyzed
5.3EPSS 0.005
CVE-2026-9667
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
Published 2026-09-10 · Analyzed
5.3EPSS 0.004
CVE-2022-39161
IBM WebSphere Application Server information disclosure
Published 2023-05-03 · Modified
5.3EPSS 0.004
CVE-2026-11538
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
Published 2026-09-18 · Analyzed
5.3EPSS 0.002
CVE-2009-1900
The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5, when tracing is enabled, allow remote attackers to obtain sensitive information via unspecified use of the wsadmin scripting tool.
Published 2009-06-03 · Modified
5.0EPSS 0.018
CVE-2007-4833
Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0.11) has unknown impact and attack vectors, aka PK44789.
Published 2007-09-12 · Modified
5.0EPSS 0.017
CVE-2008-2550
Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.17 has unknown impact and attack vectors related to an attribute in the SOAP security header.
Published 2008-06-04 · Modified
5.0EPSS 0.016
CVE-2007-1944
The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.
Published 2007-04-11 · Modified
5.0EPSS 0.016
← Prev5 / 6Next →