VendorsIBMwebsphere_extreme_scaleall versions
Vulnerabilities

IBM Websphere Extreme Scale

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2026-13773
IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used as Transport Protocol
Published 2026-06-30 · Analyzed
10.0EPSS 0.061
CVE-2026-13772
IBM WebSphere eXtreme Scale's OQL is affected by remote code execution
Published 2026-06-30 · Analyzed
9.9EPSS 0.005
CVE-2026-13759
IBM WebSphere eXtreme Scale is affected by Insecure Deserilization
Published 2026-06-30 · Analyzed
8.8EPSS 0.005
CVE-2013-5393
The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 does not properly process logoff actions, which has unspecified impact and remote attack vectors.
Published 2013-10-16 · Modified
7.5EPSS 0.013
CVE-2026-9002
IBM WebSphere eXtremes Scale is affected by uncontrolled resource consumption when XDF is enabled
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2016-0400
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Published 2016-07-02 · Modified
6.11 PoCEPSS 0.021
CVE-2019-4109
IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 158102.
Published 2019-09-30 · Modified
6.1EPSS 0.013
CVE-2015-2026
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Published 2015-10-04 · Modified
6.0EPSS 0.005
CVE-2019-4115
IBM WebSphere eXtreme Scale 8.6 Admin API is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158113.
Published 2019-09-30 · Modified
5.4EPSS 0.007
CVE-2020-4336
IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 177932.
Published 2021-01-06 · Modified
5.3EPSS 0.010
CVE-2015-2030
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack.
Published 2015-10-04 · Modified
5.0EPSS 0.014
CVE-2015-4936
Unspecified vulnerability in IBM WebSphere eXtreme Scale 8.6 through 8.6.0.8 allows remote attackers to cause a denial of service via unknown vectors.
Published 2015-08-03 · Modified
5.0EPSS 0.012
CVE-2013-5394
The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to conduct phishing attacks via unspecified vectors.
Published 2013-10-16 · Modified
4.9EPSS 0.010
CVE-2019-4106
IBM WebSphere eXtreme Scale 8.6 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158099.
Published 2019-09-30 · Modified
4.8EPSS 0.007
CVE-2015-7418
IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory instead of being overwritten which could allow a local user with administrator privileges to obtain sensitive information.
Published 2017-02-08 · Modified
4.4EPSS 0.004
CVE-2015-2025
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Published 2015-10-04 · Modified
4.3EPSS 0.012
CVE-2015-2028
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Published 2015-10-04 · Modified
4.3EPSS 0.012
CVE-2015-2029
Session fixation vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to hijack web sessions via a session identifier.
Published 2015-10-04 · Modified
4.3EPSS 0.012
CVE-2016-2861
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
Published 2016-07-02 · Modified
4.3EPSS 0.011
CVE-2019-4112
IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158105.
Published 2019-09-30 · Modified
4.0EPSS 0.003
CVE-2015-2031
Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Published 2015-10-04 · Modified
3.5EPSS 0.010
CVE-2013-5390
Cross-site scripting (XSS) vulnerability in the monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Published 2013-10-16 · Modified
3.5EPSS 0.009
CVE-2015-2027
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
Published 2015-10-04 · Modified
2.1EPSS 0.005