VYPR

Websphere Application Server

by IBM

CVEs (528)

  • CVE-2016-0378LowNov 24, 2016
    risk 0.24cvss 3.7epss 0.02

    IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3, when the installation lacks a default error page, allows remote attackers to obtain sensitive information by triggering an exception.

  • CVE-2019-4271LowSep 17, 2019
    risk 0.23cvss 3.5epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin console is vulnerable to a Client-side HTTP parameter pollution vulnerability. IBM X-Force ID: 160243.

  • CVE-2020-4629LowSep 30, 2020
    risk 0.21cvss 3.3epss 0.00

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.

  • CVE-2017-1681LowJan 11, 2018
    risk 0.21cvss 3.3epss 0.00

    IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitive information, caused by improper handling of application requests, which could allow unauthorized access to read a file. IBM X-Force ID: 134003.

  • CVE-2017-1381LowJul 21, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152.

  • CVE-2026-16190LowSep 14, 2026
    risk 0.20cvss 3.1epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

  • CVE-2018-1902LowMar 11, 2019
    risk 0.20cvss 3.1epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof connection information which could be used to launch further attacks against the system. IBM X-Force ID: 152531.

  • CVE-2016-0385LowSep 1, 2016
    risk 0.20cvss 3.1epss 0.02

    Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.10, 9.0 before 9.0.0.1, and Liberty before 16.0.0.3, when HttpSessionIdReuse is enabled, allows remote authenticated users to obtain sensitive information via…

  • CVE-2010-0425Mar 5, 2010
    risk 0.04cvss —epss 0.94

    modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which…

  • CVE-2005-3498Nov 4, 2005
    risk 0.04cvss —epss 0.11

    IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain…

  • CVE-2005-1112May 2, 2005
    risk 0.04cvss —epss 0.09

    IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web…

  • CVE-2000-0848Nov 14, 2000
    risk 0.04cvss —epss 0.06

    Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.

  • CVE-2000-0652Jul 24, 2000
    risk 0.04cvss —epss 0.08

    IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.

  • CVE-2010-3271Jul 18, 2011
    risk 0.03cvss —epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that…

  • CVE-2009-0855Mar 9, 2009
    risk 0.03cvss —epss 0.06

    Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2007-5944Nov 14, 2007
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header. NOTE: this might be the same issue as…

  • CVE-2006-2431May 17, 2006
    risk 0.03cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via…

  • CVE-2001-0390Jul 2, 2001
    risk 0.03cvss —epss 0.05

    IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.

  • CVE-2001-0122Mar 13, 2001
    risk 0.03cvss —epss 0.03

    Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.

  • CVE-2015-1920May 20, 2015
    risk 0.01cvss —epss 0.07

    IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.

Page 13 of 27