VendorsIBMwebsphere_application_server8.5
Vulnerabilities

IBM WebSphere Application Server 8.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2015-7450
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.
Published 2016-01-02 · Analyzed
10.0KEV1 PoCEPSS 0.978
CVE-2023-23477
IBM WebSphere Application Server code execution
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2017-1194
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.
Published 2017-04-28 · Modified
8.8EPSS 0.009
CVE-2020-4534
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this vulnerability to execute arbitrary code with higher privileges. IBM X-Force ID: 182808.
Published 2020-08-03 · Modified
8.8EPSS 0.004
CVE-2017-1151
IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could allow a user to gain elevated privileges on the system. IBM Reference #: 1999293.
Published 2017-03-20 · Modified
8.1EPSS 0.022
CVE-2017-1137
IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549.
Published 2017-05-10 · Modified
8.1EPSS 0.019
CVE-2018-1614
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker to obtain sensitive information. IBM X-Force ID: 144270.
Published 2018-06-26 · Modified
7.5EPSS 0.029
CVE-2021-38951
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405.
Published 2021-12-09 · Modified
7.5EPSS 0.015
CVE-2022-43917
IBM WebSphere Application Server information disclosure
Published 2023-01-25 · Modified
7.5EPSS 0.005
CVE-2019-4732
IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 172618.
Published 2020-02-03 · Modified
7.2EPSS 0.006
CVE-2023-50313
IBM WebSphere Application Server information disclosure
Published 2024-04-02 · Modified
6.5EPSS 0.002
CVE-2017-1503
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 129578.
Published 2017-10-10 · Modified
6.1EPSS 0.017
CVE-2018-1793
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148948.
Published 2018-10-03 · Modified
6.1EPSS 0.014
CVE-2022-22477
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605.
Published 2022-07-14 · Modified
6.1EPSS 0.006
CVE-2017-1121
IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997743
Published 2017-02-13 · Modified
5.4EPSS 0.009
CVE-2022-34336
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229714.
Published 2022-09-13 · Modified
5.4EPSS 0.005
CVE-2022-40750
IBM WebSphere Application Server cross-site scripting
Published 2022-11-11 · Modified
5.4EPSS 0.004
CVE-2016-9736
IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.
Published 2017-06-08 · Modified
5.3EPSS 0.023
CVE-2022-39161
IBM WebSphere Application Server information disclosure
Published 2023-05-03 · Modified
5.3EPSS 0.004
CVE-2024-45073
IBM WebSphere Application Server cross-site scripting
Published 2024-09-30 · Analyzed
4.8EPSS 0.002
CVE-2024-45087
IBM WebSphere Application Server cross-site scripting
Published 2024-11-11 · Analyzed
4.8EPSS 0.002
CVE-2017-1741
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could read files on the file system. IBM X-Force ID: 134931.
Published 2018-03-14 · Modified
4.3EPSS 0.020
CVE-2017-1743
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could browse the file system. IBM X-Force ID: 134933.
Published 2018-05-04 · Modified
4.3EPSS 0.019