VYPR

WebSphere Application Server Liberty Profile

by IBM

CVEs (48)

  • CVE-2024-56339LowAug 7, 2025
    risk 0.24cvss 3.7epss 0.00

    IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.

  • CVE-2016-0378LowNov 24, 2016
    risk 0.24cvss 3.7epss 0.02

    IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3, when the installation lacks a default error page, allows remote attackers to obtain sensitive information by triggering an exception.

  • CVE-2015-1882Apr 27, 2015
    risk 0.00cvss epss 0.03

    Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.

  • CVE-2014-8890Dec 18, 2014
    risk 0.00cvss epss 0.02

    IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations.

  • CVE-2014-4767Aug 22, 2014
    risk 0.00cvss epss 0.03

    IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticated users to execute arbitrary code via unspecified vectors.

  • CVE-2014-0896May 1, 2014
    risk 0.00cvss epss 0.02

    IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information via a crafted request.

  • CVE-2013-4006Nov 18, 2013
    risk 0.00cvss epss 0.01

    IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.

  • CVE-2013-0540Apr 24, 2013
    risk 0.00cvss epss 0.02

    IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.

Page 3 of 3