Skip to main content

Vendor/product archive

ibm / websphere_application_server CVEs

Beta · best-effort

468 CVEs tagged to ibm / websphere_application_server50 Critical, 89 High, 288 Medium, 41 Low, 0 Unrated.

CVE-2017-1194

Published Apr 28, 2017

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1151

Published Mar 20, 2017

IBM WebSphere Application Server 8.0, 8.5, 8.5.5, and 9.0 using OpenID Connect (OIDC) configured with a Trust Association Interceptor (TAI) could allow a user to gain elevated pri…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1121

Published Feb 13, 2017

IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8919

Published Feb 1, 2017

IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and cause the consumption of resourc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8934

Published Feb 1, 2017

IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0378

Published Nov 24, 2016

IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3, when the installation lacks a default error page, allows remote attackers to obtain sensitive information by trigge…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-0377

Published Oct 22, 2016

The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5983

Published Oct 5, 2016

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5986

Published Oct 1, 2016

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3042

Published Oct 1, 2016

Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0385

Published Sep 1, 2016

Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.10, 9.0 before 9.0.0.1, and Liberty before 16.0.0.3, when Http…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2960

Published Aug 8, 2016

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2945

Published Jul 8, 2016

The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote authenticated users to ga…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2923

Published Jul 7, 2016

IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified JA…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0389

Published Jul 7, 2016

Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to obtain sensitive information via…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0359

Published Jul 3, 2016

CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 Full before 8.5.5.10, and 8.5 Liberty before Liberty Fix Pack…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0306

Published May 17, 2016

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-mi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0283

Published Mar 19, 2016

Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7417

Published Jan 23, 2016

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7450

Published Jan 2, 2016

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed

CVE-2015-5004

Published Dec 15, 2015

The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authentic…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2017

Published Nov 8, 2015

CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attacke…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4938

Published Aug 22, 2015

IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 468 CVEsPage 8 of 19