← Back

Websphere Application Server

websphere_application_server

Vendor: Ibm • 465 CVEs

CVEs (465)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Websphere Application Server
Apr 23, 2026
Mar 20, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure file...Show more
SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Dec 19, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP s...Show more
The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and other sensitive information via "specific requests."Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Dec 19, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.
1Ibm
1Websphere Application Server
Apr 23, 2026
Nov 28, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authentication checks at the proper time during "registering of response operation," which has unknown impact and attack vectors.
1Ibm
1Websphere Application Server
Apr 23, 2026
Nov 28, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, related to (1) a "Potential security vulnerability" (PK29725) and (2) "Po...Show more
Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, related to (1) a "Potential security vulnerability" (PK29725) and (2) "Potential security exposure" (PK30831).Show less
1Ibm
1Websphere Application Server
Apr 23, 2026
Oct 17, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
The Web Services Notification (WSN) security component of IBM WebSphere Application Server before 6.1.0.2 allows attackers to obtain unspecified access without supplying a username and password, aka PK28374.
1Ibm
1Websphere Application Server
Apr 23, 2026
Oct 17, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360.
1Ibm
1Websphere Application Server
Apr 16, 2026
Aug 18, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web...Show more
IBM WebSphere Application Server (WAS) before 6.0.2.13 allows context-dependent attackers to obtain sensitive information via unspecified vectors related to "JSP source code exposure" (PK23475), which occurs when ibm-web-ext.xmi sets fileServingEnabled to true or ExtendedDocumentRoot is used to place a JSP outside a WAR.file; (3) the First Failure Data Capture (ffdc) log file (PK24834); and (4) traces (PK25568), a different issue than CVE-2006-4137.Show less
1Ibm
1Websphere Application Server
Apr 16, 2026
Aug 18, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspecified vectors and impact, including (1) an "authority problem" in ThreadIdentitySupport as identified by PK25199, and "P...Show more
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspecified vectors and impact, including (1) an "authority problem" in ThreadIdentitySupport as identified by PK25199, and "Potential security exposure" issues as identified by (2) PK22747, (3) PK24334, (4) PK25740, and (5) PK26123.Show less
1Ibm
1Websphere Application Server
Apr 16, 2026
Aug 14, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.
1Ibm
1Websphere Application Server
Apr 16, 2026
Aug 14, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadIdentitySupport, and po...Show more
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadIdentitySupport, and possibly others.Show less
1Ibm
1Websphere Application Server
Apr 16, 2026
Jun 27, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."
1Ibm
1Websphere Application Server
Apr 16, 2026
Jun 27, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with speci...Show more
Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."Show less
1Ibm
1Websphere Application Server
Apr 16, 2026
May 17, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.
1Ibm
1Websphere Application Server
Apr 16, 2026
May 17, 2006
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended...Show more
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."Show less
1Ibm
1Websphere Application Server
Apr 16, 2026
May 17, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace.
1Ibm
1Websphere Application Server
Apr 16, 2026
May 17, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".
1Ibm
1Websphere Application Server
Apr 16, 2026
May 17, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.
1Ibm
1Websphere Application Server
Apr 16, 2026
May 17, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows rem...Show more
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.Show less
1Ibm
1Websphere Application Server
Apr 16, 2026
May 17, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.