VendorsIBMwebsphere_application_server9.0.0.0
Vulnerabilities

IBM WebSphere Application Server 9.0.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-8400
Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
Published 2026-08-05 · Analyzed
9.8EPSS 0.005
CVE-2024-37532
IBM WebSphere Application Server identity spoofing
Published 2024-06-20 · Modified
8.8EPSS 0.004
CVE-2016-5983
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.
Published 2016-10-05 · Modified
7.5EPSS 0.041
CVE-2016-5986
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain sensitive information via unspecified vectors.
Published 2016-10-01 · Modified
7.5EPSS 0.024
CVE-2023-30441
IBM Java information disclosure
Published 2023-04-29 · Modified
7.5EPSS 0.006
CVE-2024-56339
IBM WebSphere Application Server information disclosure
Published 2025-08-07 · Analyzed
7.5EPSS 0.004
CVE-2018-1621
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346.
Published 2018-07-06 · Modified
6.7EPSS 0.003
CVE-2018-1838
IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords. IBM X-Force ID: 150811.
Published 2018-10-12 · Modified
6.5EPSS 0.016
CVE-2017-1501
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web services security bindings settings. IBM X-Force ID: 129576.
Published 2017-08-18 · Modified
5.9EPSS 0.020
CVE-2023-50315
IBM WebSphere Application Server information disclosure
Published 2024-08-14 · Analyzed
5.9EPSS 0.003
CVE-2016-8934
IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2017-02-01 · Modified
5.4EPSS 0.007
CVE-2025-13333
IBM WebSphere Application Server could provide weaker than expected security
Published 2026-02-17 · Analyzed
4.9EPSS 0.003
CVE-2025-36099
IBM WebSphere Application Server denial of service
Published 2025-09-29 · Analyzed
4.9EPSS 0.003
CVE-2016-2960
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.
Published 2016-08-08 · Modified
4.3EPSS 0.396
CVE-2016-0385
Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.10, 9.0 before 9.0.0.1, and Liberty before 16.0.0.3, when HttpSessionIdReuse is enabled, allows remote authenticated users to obtain sensitive information via unspecified vectors.
Published 2016-09-01 · Modified
3.5EPSS 0.014