VendorsIBMwebsphere_application_serverany version
Vulnerabilities

IBM WebSphere Application Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

236CVEs
CVE-2010-0425
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
Published 2010-03-05 · Analyzed
10.02 PoCEPSS 0.942
CVE-2019-4279
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.
Published 2019-05-17 · Modified
10.01 PoCEPSS 0.799
CVE-2020-4450
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
Published 2020-06-05 · Modified
10.0EPSS 0.342
CVE-2020-4448
IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.
Published 2020-06-05 · Modified
10.0EPSS 0.122
CVE-2020-4589
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.
Published 2020-08-13 · Modified
10.0EPSS 0.085
CVE-2012-5955
Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown vectors.
Published 2012-12-20 · Modified
10.0EPSS 0.044
CVE-2009-1899
Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5 on z/OS allows remote authenticated users to obtain sensitive information via unknown use of the wsadmin scripting tool, related to a "security exposure in wsadmin."
Published 2009-06-03 · Modified
10.0EPSS 0.043
CVE-2008-4283
CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Published 2009-02-10 · Modified
10.0EPSS 0.033
CVE-2006-7198
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and attack vectors, related to a "Potential security exposure," aka PK26123.
Published 2007-04-30 · Modified
10.0EPSS 0.024
CVE-2007-6679
Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 before Fix Pack 13 has unknown impact and attack vectors, related to "security concerns with monitor role users." NOTE: it was later reported that 6.0.2 before Fix Pack 25 is also affected.
Published 2008-01-10 · Modified
10.0EPSS 0.023
CVE-2008-5412
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs. NOTE: this is probably a duplicate of CVE-2009-0438.
Published 2008-12-10 · Modified
10.0EPSS 0.023
CVE-2007-3263
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface to the SDO repository."
Published 2007-06-19 · Modified
10.0EPSS 0.023
CVE-2006-5323
Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360.
Published 2006-10-17 · Modified
10.0EPSS 0.022
CVE-2008-0389
Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.
Published 2008-01-23 · Modified
10.0EPSS 0.021
CVE-2008-0741
Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has unknown impact and attack vectors.
Published 2008-02-13 · Modified
10.0EPSS 0.018
CVE-2007-3264
Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors.
Published 2007-06-19 · Modified
10.0EPSS 0.018
CVE-2009-1901
The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact and remote attack vectors.
Published 2009-06-03 · Modified
10.0EPSS 0.015
CVE-2025-36038
IBM WebSphere Application Server code execution
Published 2025-06-25 · Analyzed
9.8EPSS 0.108
CVE-2018-1851
IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vulnerability to execute arbitrary code. IBM X-Force ID: 150999.
Published 2018-10-31 · Modified
9.8EPSS 0.039
CVE-2018-1567
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources. IBM X-Force ID: 143024.
Published 2018-09-07 · Modified
9.8EPSS 0.038
CVE-2018-1904
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.
Published 2018-12-11 · Modified
9.8EPSS 0.037
CVE-2011-4889
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.
Published 2018-02-08 · Modified
9.8EPSS 0.027
CVE-2026-8633
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins
Published 2026-05-26 · Analyzed
9.8EPSS 0.009
CVE-2026-14512
IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
Published 2026-07-28 · Analyzed
9.8EPSS 0.006
CVE-2026-11541
Inconsistent Interpretation of HTTP Requests in CICS Transaction Gateway for Multiplatforms.
Published 2026-06-30 · Modified
9.8EPSS 0.004
CVE-2025-14917
IBM WebSphere Application Server Liberty could provide weaker than expected security
Published 2026-03-25 · Analyzed
9.8EPSS 0.004
CVE-2026-11546
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability
Published 2026-06-30 · Analyzed
9.8EPSS 0.004
CVE-2026-14529
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery
Published 2026-07-29 · Analyzed
9.8EPSS 0.004
CVE-2026-14974
IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities
Published 2026-07-28 · Analyzed
9.8EPSS 0.004
CVE-2026-11714
IBM WebSphere Application Server Liberty is affected by an authorization bypass vulnerability
Published 2026-06-30 · Modified
9.8EPSS 0.004
CVE-2026-14446
IBM WebSphere Application Server is affected by a privilege escalation
Published 2026-07-28 · Analyzed
9.8EPSS 0.003
CVE-2026-16184
IBM WebSphere Application Server is affected by an authentication bypass
Published 2026-07-28 · Analyzed
9.8EPSS 0.003
CVE-2026-14976
IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability
Published 2026-07-28 · Analyzed
9.8EPSS 0.003
CVE-2026-8400
Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
Published 2026-08-05 · Analyzed
9.8EPSS 0.003
CVE-2025-14923
IBM WebSphere Application Server Liberty could provide weaker than expected security
Published 2026-03-03 · Analyzed
9.8EPSS 0.002
CVE-2026-14525
IBM WebSphere Application Server Liberty is affected by an authenication bypass
Published 2026-08-13 · Analyzed
9.4EPSS 0.003
CVE-2007-3960
Multiple unspecified vulnerabilities in IBM WebSphere Application Server (WAS) before Fix Pack 21 (6.0.2.21) have unknown impact and attack vectors, aka (1) PK33799, or (2) a "Potential security exposure" in the Samples component (PK40213).
Published 2007-07-24 · Modified
9.3EPSS 0.019
CVE-2026-11712
IBM WebSphere Application Server is affected by a cross-site scripting vulnerability
Published 2026-06-30 · Analyzed
9.3EPSS 0.004
CVE-2026-11708
IBM WebSphere Application Server is affected by a cross-site scripting vulnerability
Published 2026-06-30 · Analyzed
9.3EPSS 0.004
CVE-2026-11707
Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
Published 2026-07-30 · Analyzed
9.3EPSS 0.002
1 / 6Next →