Skip to main content

Vendor/product archive

ibm / websphere_application_server CVEs

Beta · best-effort

468 CVEs tagged to ibm / websphere_application_server50 Critical, 89 High, 288 Medium, 41 Low, 0 Unrated.

CVE-2013-0597

Published Aug 21, 2013

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0, when OAuth is used, allows remo…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-0565

Published Apr 24, 2013

Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IBM WebSphere Application Server (WAS) 8.5 before 8.5.0.2 allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0542

Published Apr 24, 2013

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0540

Published Apr 24, 2013

IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenti…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-0462

Published Jan 27, 2013

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1, 7.0 before 7.0.0.27, 8.0, and 8.5 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0461

Published Jan 27, 2013

Cross-site scripting (XSS) vulnerability in the virtual member manager (VMM) administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0460

Published Jan 27, 2013

Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 and 7.0 before…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0459

Published Jan 27, 2013

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0458

Published Jan 27, 2013

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5955

Published Dec 20, 2012

Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4853

Published Nov 14, 2012

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows rem…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4851

Published Nov 14, 2012

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4850

Published Nov 14, 2012

IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote attackers to gain privileges via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-3330

Published Nov 14, 2012

The proxy server in IBM WebSphere Application Server 7.0 before 7.0.0.27, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, and WebSphere Virtual Enterprise, allows remote attackers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3311

Published Sep 25, 2012

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3306

Published Sep 25, 2012

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purg…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3305

Published Sep 25, 2012

Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote atta…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3304

Published Sep 25, 2012

The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3325

Published Aug 30, 2012

IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, when the PM44303 fix is installed…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3293

Published Aug 21, 2012

Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 468 CVEsPage 11 of 19