VYPR

Websphere Application Server

by IBM

CVEs (498)

  • CVE-2021-39031HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.02

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to…

  • CVE-2021-29736HigJul 30, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.

  • CVE-2021-29754HigJun 11, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.

  • CVE-2021-20517HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.02

    IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to read and delete arbitrary files on the system. IBM…

  • CVE-2020-4534HigAug 3, 2020
    risk 0.57cvss 8.8epss 0.00

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this…

  • CVE-2020-4362HigApr 10, 2020
    risk 0.57cvss 8.8epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.

  • CVE-2017-1731HigJan 30, 2018
    risk 0.57cvss 8.8epss 0.03

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.

  • CVE-2017-1194HigApr 28, 2017
    risk 0.57cvss 8.8epss 0.01

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.

  • CVE-2026-11536HigJul 30, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

  • CVE-2026-11714HigJun 30, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

  • CVE-2026-9330HigJun 1, 2026
    risk 0.55cvss 8.5epss 0.01

    IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable…

  • CVE-2021-20454HigApr 21, 2021
    risk 0.54cvss 8.2epss 0.03

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.

  • CVE-2021-20453HigApr 20, 2021
    risk 0.54cvss 8.2epss 0.03

    IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648.

  • CVE-2021-20353HigFeb 10, 2021
    risk 0.54cvss 8.2epss 0.05

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.

  • CVE-2020-4949HigJan 26, 2021
    risk 0.54cvss 8.2epss 0.05

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.

  • CVE-2026-8400HigAug 5, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.

  • CVE-2026-14974HigJul 28, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.

  • CVE-2026-9072HigJun 22, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker…

  • CVE-2023-23477HigFeb 3, 2023
    risk 0.53cvss 8.1epss 0.02

    IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513.

  • CVE-2021-20492HigMay 26, 2021
    risk 0.53cvss 8.2epss 0.02

    IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM…

Page 2 of 25