VYPR

Websphere Application Server

by IBM

CVEs (528)

  • CVE-2025-13333MedFeb 17, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.

  • CVE-2025-36000MedAug 12, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to…

  • CVE-2025-33104MedMay 14, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

  • CVE-2018-1621MedJul 6, 2018
    risk 0.29cvss 4.4epss 0.00

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346.

  • CVE-2026-11537MedSep 18, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

  • CVE-2024-22329MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to conduct the SSRF attack.…

  • CVE-2020-4365MedMay 14, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.

  • CVE-2020-4329MedApr 28, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenticated attacker to obtain sensitive information, caused by improper parameter checking. This could be exploited to conduct spoofing attacks. IBM X-Force ID:…

  • CVE-2019-4442MedSep 17, 2019
    risk 0.28cvss 4.3epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse directories on the file system. An attacker could send a specially-crafted URL request to view arbitrary files on the system but not content. IBM X-Force ID: 163226.

  • CVE-2018-1926MedDec 12, 2018
    risk 0.28cvss 4.3epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious URL, a remote attacker could send a specially-crafted request. An…

  • CVE-2017-1743MedMay 4, 2018
    risk 0.28cvss 4.3epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could browse the file system. IBM X-Force ID: 134933.

  • CVE-2017-1741MedMar 14, 2018
    risk 0.28cvss 4.3epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could read files on the file system. IBM X-Force ID: 134931.

  • CVE-2016-0377MedOct 22, 2016
    risk 0.28cvss 4.3epss 0.02

    The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

  • CVE-2026-10841MedSep 18, 2026
    risk 0.27cvss 4.2epss 0.00

    IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.

  • CVE-2025-27907MedApr 22, 2025
    risk 0.27cvss 4.1epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

  • CVE-2016-2960LowAug 8, 2016
    risk 0.27cvss 3.7epss 0.11

    IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.

  • CVE-2018-1957MedDec 10, 2018
    risk 0.26cvss 4.0epss 0.00

    IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629.

  • CVE-2026-11545LowSep 18, 2026
    risk 0.24cvss 3.7epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.

  • CVE-2026-11538LowSep 18, 2026
    risk 0.24cvss 3.7epss 0.00

    IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.

  • CVE-2024-56339LowAug 7, 2025
    risk 0.24cvss 3.7epss 0.00

    IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.

Page 12 of 27