Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm websphere application server 2.0 vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv3
CVE-2016-3040
IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x prior to 2.0.2 FP8, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Ibm Security Privileged Identity Manager Virtual Appliance 2.0
6.5
CVSSv3
CVE-2020-4590
IBM WebSphere Application Server Liberty 17.0.0.3 up to and including 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.
Ibm Websphere Application Server
NA
CVE-2013-0565
Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IBM WebSphere Application Server (WAS) 8.5 prior to 8.5.0.2 allows remote malicious users to inject arbitrary web script or HTML via a crafted response.
Ibm Websphere Application Server 8.5.0.1
Ibm Websphere Application Server 8.5.0.0
NA
CVE-2011-1360
Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and previous versions, as used in WebSphere Application Server and other products, allow remote malicious users to inject arbitrary web script or HTML via vectors involving unspecified documentation fil...
Ibm Http Server
Ibm Http Server 1.3.19
Ibm Http Server 1.3.12.2
Ibm Http Server 1.3.28
Ibm Http Server 2.0.42.1
Ibm Http Server 1.3.19.4
Ibm Http Server 1.0
Ibm Http Server 2.0.42
Ibm Http Server 1.3.19.5
Ibm Http Server 2.0
Ibm Http Server 1.3.12
Ibm Http Server 1.3.19.6
Ibm Http Server 1.3.28.1
Ibm Http Server 1.3.26.1
Ibm Http Server 2.0.42.2
Ibm Http Server 1.3.6.3
Ibm Http Server 1.3.12.7
Ibm Http Server 1.3.26
Ibm Http Server 1.3.12.6
Ibm Http Server 1.3.26.2
NA
CVE-2010-3271
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and previous versions allow remote malicious users to hijack the authentication of administrators for req...
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 6.1.0.21
Ibm Websphere Application Server 6.1.0.31
Ibm Websphere Application Server 3.0.21
Ibm Websphere Application Server 6.1.7
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 6.1
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 6.1.6
Ibm Websphere Application Server 3.0.2.1
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 6.0.2.5
Ibm Websphere Application Server 6.0.0.3
Ibm Websphere Application Server 6.1.0.2
1 EDB exploit
NA
CVE-2011-1307
The installer in IBM WebSphere Application Server (WAS) prior to 7.0.0.15 uses 777 permissions for a temporary log directory, which allows local users to have unintended access to log files via standard filesystem operations, a different vulnerability than CVE-2009-1173.
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 6.1.0.21
Ibm Websphere Application Server 6.1.0.31
Ibm Websphere Application Server 3.0.21
Ibm Websphere Application Server 6.1.7
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 6.1
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 6.1.6
Ibm Websphere Application Server 3.0.2.1
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 6.0.2.5
Ibm Websphere Application Server 6.0.0.3
Ibm Websphere Application Server 6.1.0.2
NA
CVE-2011-1308
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) prior to 7.0.0.15 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 6.1.0.21
Ibm Websphere Application Server 6.1.0.31
Ibm Websphere Application Server 3.0.21
Ibm Websphere Application Server 6.1.7
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 6.1
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 6.1.6
Ibm Websphere Application Server 3.0.2.1
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 6.0.2.5
Ibm Websphere Application Server 6.0.0.3
Ibm Websphere Application Server 6.1.0.2
NA
CVE-2011-1311
The Security component in IBM WebSphere Application Server (WAS) prior to 7.0.0.15, when a J2EE 1.4 application is used, determines the security role mapping on the basis of the ibm-application-bnd.xml file instead of the intended ibm-application-bnd.xmi file, which might allow r...
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 6.1.0.21
Ibm Websphere Application Server 6.1.0.31
Ibm Websphere Application Server 3.0.21
Ibm Websphere Application Server 6.1.7
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 6.1
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 6.1.6
Ibm Websphere Application Server 3.0.2.1
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 6.0.2.5
Ibm Websphere Application Server 6.0.0.3
Ibm Websphere Application Server 6.1.0.2
NA
CVE-2011-1314
The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) prior to 7.0.0.15 allows remote malicious users to cause a denial of service (daemon hang) by performing close operations via network connections to a queue manager.
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 6.1.0.21
Ibm Websphere Application Server 6.1.0.31
Ibm Websphere Application Server 3.0.21
Ibm Websphere Application Server 6.1.7
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 6.1
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 6.1.6
Ibm Websphere Application Server 3.0.2.1
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 6.0.2.5
Ibm Websphere Application Server 6.0.0.3
Ibm Websphere Application Server 6.1.0.2
NA
CVE-2011-1315
Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) prior to 7.0.0.15 allows remote malicious users to cause a denial of service (memory consumption) via network connections associated with a NULL return value from a synchronous JMS receive call.
Ibm Websphere Application Server 5.0.0
Ibm Websphere Application Server 6.1.0.21
Ibm Websphere Application Server 6.1.0.31
Ibm Websphere Application Server 3.0.21
Ibm Websphere Application Server 6.1.7
Ibm Websphere Application Server 5.1.0.5
Ibm Websphere Application Server 6.1
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 5.0.2.10
Ibm Websphere Application Server 5.1.1.14
Ibm Websphere Application Server 5.0.2.5
Ibm Websphere Application Server 5.0.2.1
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 5.1.1.2
Ibm Websphere Application Server 6.1.6
Ibm Websphere Application Server 3.0.2.1
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 5.0
Ibm Websphere Application Server 6.0.2.1
Ibm Websphere Application Server 6.0.2.5
Ibm Websphere Application Server 6.0.0.3
Ibm Websphere Application Server 6.1.0.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4541
CVE-2024-3080
CVE-2024-4787
log injection
CVE-2024-5967
inject
CVE-2024-30078
CVE-2024-5899
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »