VYPR

Websphere Application Server

by IBM

CVEs (528)

  • CVE-2025-33142MedAug 14, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.

  • CVE-2023-50314MedAug 14, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. …

  • CVE-2023-50315MedAug 14, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274714.

  • CVE-2023-50313MedApr 2, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274812.

  • CVE-2023-50312MedMar 1, 2024
    risk 0.34cvss 5.3epss 0.01

    IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274711.

  • CVE-2023-35890MedJul 7, 2023
    risk 0.33cvss 5.1epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637.

  • CVE-2018-1901MedDec 12, 2018
    risk 0.33cvss 5.0epss 0.01

    IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.

  • CVE-2025-36099MedSep 29, 2025
    risk 0.32cvss 4.9epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A privileged user could exploit this vulnerability to cause the server to consume memory resources.

  • CVE-2023-46158MedOct 25, 2023
    risk 0.32cvss 4.9epss 0.00

    IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.

  • CVE-2026-11722MedSep 18, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

  • CVE-2026-11548MedSep 18, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

  • CVE-2026-16189MedSep 14, 2026
    risk 0.31cvss 4.8epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

  • CVE-2026-4410MedMay 27, 2026
    risk 0.31cvss 4.8epss 0.01

    IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit…

  • CVE-2025-14923MedMar 3, 2026
    risk 0.31cvss 4.7epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.

  • CVE-2024-45087MedNov 11, 2024
    risk 0.31cvss 4.8epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…

  • CVE-2024-45073MedSep 30, 2024
    risk 0.31cvss 4.8epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…

  • CVE-2024-35153MedJun 27, 2024
    risk 0.31cvss 4.8epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…

  • CVE-2024-27270MedMar 27, 2024
    risk 0.31cvss 4.7epss 0.00

    IBM WebSphere Application Server Liberty 23.0.0.3 through 24.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in a specially crafted URI. IBM X-Force ID: 284576.

  • CVE-2022-39161MedMay 3, 2023
    risk 0.31cvss 4.8epss 0.00

    IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server Plug-ins for IBM WebSphere Application Server, could allow an authenticated user to conduct spoofing attacks. A man-in-the-middle…

  • CVE-2026-5516MedMay 27, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.

Page 11 of 27