Skip to main content

Vendor/product archive

ibm / websphere_application_server CVEs

Beta · best-effort

488 CVEs tagged to ibm / websphere_application_server53 Critical, 104 High, 289 Medium, 42 Low, 0 Unrated.

CVE-2015-1885

Published Apr 27, 2015

WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1882

Published Apr 27, 2015

Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conf…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0175

Published Apr 27, 2015

IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenticated users to gain privileges…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0174

Published Apr 27, 2015

The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8890

Published Dec 18, 2014

IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6174

Published Dec 18, 2014

IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to conduct clickjacking attacks via a crafted web sit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6167

Published Dec 18, 2014

Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6166

Published Dec 18, 2014

The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6164

Published Dec 18, 2014

IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensiti…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3021

Published Oct 19, 2014

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obt…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4816

Published Sep 23, 2014

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4770

Published Sep 23, 2014

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows re…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-4767

Published Aug 22, 2014

IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticate…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4764

Published Aug 22, 2014

IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3083

Published Aug 22, 2014

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource access, which allows remote attac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3070

Published Aug 22, 2014

The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3022

Published Aug 22, 2014

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0965

Published Aug 22, 2014

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0891

Published Jun 28, 2014

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information by leveraging…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0964

Published May 16, 2014

IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demon…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 226-250 of 488 CVEsPage 10 of 20