← Back

Websphere Application Server

websphere_application_server

Vendor: Ibm • 492 CVEs

CVEs (492)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Websphere Application Server
Aug 5, 2026
Jul 28, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
1Ibm
1Websphere Application Server
Aug 5, 2026
Jul 28, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
1Ibm
1Websphere Application Server
Aug 5, 2026
Jul 28, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
1Ibm
1Websphere Application Server
Aug 5, 2026
Jul 28, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
1Ibm
1Websphere Application Server
Aug 5, 2026
Jul 28, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
1Ibm
1Websphere Application Server
Aug 3, 2026
Jul 28, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled.
1Ibm
1Websphere Application Server
Aug 3, 2026
Jul 28, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
1Ibm
1Websphere Application Server
Jul 29, 2026
Jun 30, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP reque...Show more
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.Show less
1Ibm
1Websphere Application Server
Jul 2, 2026
Jun 30, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.
1Ibm
1Websphere Application Server
Jul 2, 2026
Jun 30, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
1Ibm
1Websphere Application Server
Aug 6, 2026
Jun 30, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
1Ibm
1Websphere Application Server
Jul 2, 2026
Jun 30, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
1Ibm
1Websphere Application Server
Jul 2, 2026
Jun 30, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
1Ibm
1Websphere Application Server
Jul 2, 2026
Jun 30, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.
1Ibm
1Websphere Application Server
Jul 2, 2026
Jun 30, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
1Ibm
1Websphere Application Server
Jun 23, 2026
Jun 22, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attack...Show more
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.Show less
1Ibm
1Websphere Application Server
Jun 23, 2026
Jun 22, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attack...Show more
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.Show less
1Ibm
1Websphere Application Server
Jun 24, 2026
Jun 22, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a s...Show more
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.Show less
1Ibm
1Websphere Application Server
Jun 24, 2026
Jun 22, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request...Show more
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.Show less
1Ibm
1Websphere Application Server
Jun 23, 2026
Jun 22, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.