VYPR

Websphere Application Server Liberty

by IBM

CVEs (38)

  • CVE-2026-10852MedJun 22, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.

  • CVE-2026-9320MedJun 22, 2026
    risk 0.38cvss 5.9epss 0.01

    IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to…

  • CVE-2026-10571MedAug 13, 2026
    risk 0.37cvss 5.7epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is…

  • CVE-2026-1561MedMar 25, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network…

  • CVE-2023-46158MedOct 25, 2023
    risk 0.32cvss 4.9epss 0.00

    IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.

  • CVE-2026-11722MedSep 18, 2026
    risk 0.31cvss 4.8epss

    IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

  • CVE-2026-11548MedSep 18, 2026
    risk 0.31cvss 4.8epss

    IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

  • CVE-2026-4410MedMay 27, 2026
    risk 0.31cvss 4.8epss 0.01

    IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit…

  • CVE-2025-14923MedMar 3, 2026
    risk 0.31cvss 4.7epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.

  • CVE-2026-5516MedMay 27, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.

  • CVE-2026-14980HigJul 30, 2026
    risk 0.00cvss 8.3epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.

  • CVE-2026-11897HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

  • CVE-2026-2482LowJul 29, 2026
    risk 0.00cvss 3.1epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

  • CVE-2026-14529CriJul 29, 2026
    risk 0.00cvss 9.4epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

  • CVE-2026-16192HigJul 28, 2026
    risk 0.00cvss 7.1epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled.

  • CVE-2026-11541HigJun 30, 2026
    risk 0.00cvss 7.4epss 0.00

    IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.

  • CVE-2026-11806HigJun 30, 2026
    risk 0.00cvss 7.2epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.

  • CVE-2026-11546HigJun 30, 2026
    risk 0.00cvss 7.1epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.

Page 2 of 2