VYPR

Websphere Application Server

by IBM

CVEs (498)

  • CVE-2000-0652Jul 24, 2000
    risk 0.04cvss epss 0.08

    IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.

  • CVE-2010-3271Jul 18, 2011
    risk 0.03cvss epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that…

  • CVE-2009-0855Mar 9, 2009
    risk 0.03cvss epss 0.06

    Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2007-5944Nov 14, 2007
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header. NOTE: this might be the same issue as…

  • CVE-2006-2431May 17, 2006
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via…

  • CVE-2001-0390Jul 2, 2001
    risk 0.03cvss epss 0.05

    IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.

  • CVE-2001-0122Mar 13, 2001
    risk 0.03cvss epss 0.03

    Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.

  • CVE-2015-1920May 20, 2015
    risk 0.01cvss epss 0.07

    IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.

  • CVE-2026-14980HigJul 30, 2026
    risk 0.00cvss 8.3epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.

  • CVE-2026-11897HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

  • CVE-2026-11707CriJul 30, 2026
    risk 0.00cvss 9.3epss 0.00

    IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.

  • CVE-2026-11383MedJul 30, 2026
    risk 0.00cvss 5.4epss 0.00

    IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console.

  • CVE-2026-2482LowJul 29, 2026
    risk 0.00cvss 3.1epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

  • CVE-2026-14529CriJul 29, 2026
    risk 0.00cvss 9.4epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

  • CVE-2026-16192HigJul 28, 2026
    risk 0.00cvss 7.1epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled.

  • CVE-2026-16184HigJul 28, 2026
    risk 0.00cvss 7.0epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.

  • CVE-2026-11541HigJun 30, 2026
    risk 0.00cvss 7.4epss 0.00

    IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.

  • CVE-2026-11594HigJun 30, 2026
    risk 0.00cvss 8.5epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.

  • CVE-2026-11806HigJun 30, 2026
    risk 0.00cvss 7.2epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.

  • CVE-2026-11712CriJun 30, 2026
    risk 0.00cvss 9.3epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

Page 12 of 25