Skip to main content

Vendor/product archive

ibm / websphere_application_server CVEs

Beta · best-effort

468 CVEs tagged to ibm / websphere_application_server50 Critical, 89 High, 288 Medium, 41 Low, 0 Unrated.

CVE-2015-1936

Published Jul 14, 2015

The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticat…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1927

Published Jul 14, 2015

The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webco…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1920

Published May 20, 2015

IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1885

Published Apr 27, 2015

WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1882

Published Apr 27, 2015

Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conf…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0175

Published Apr 27, 2015

IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenticated users to gain privileges…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0174

Published Apr 27, 2015

The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8890

Published Dec 18, 2014

IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6174

Published Dec 18, 2014

IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to conduct clickjacking attacks via a crafted web sit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6167

Published Dec 18, 2014

Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6166

Published Dec 18, 2014

The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6164

Published Dec 18, 2014

IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensiti…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3021

Published Oct 19, 2014

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obt…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4816

Published Sep 23, 2014

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4770

Published Sep 23, 2014

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows re…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-4767

Published Aug 22, 2014

IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticate…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4764

Published Aug 22, 2014

IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3083

Published Aug 22, 2014

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource access, which allows remote attac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3070

Published Aug 22, 2014

The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3022

Published Aug 22, 2014

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 468 CVEsPage 9 of 19