Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm websphere application server liberty vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2019-4441
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote malicious user to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.
Ibm Websphere Application Server
7.5
CVSSv3
CVE-2019-4720
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available memory. IBM X-Force ID: 172125.
Ibm Websphere Application Server
6.1
CVSSv3
CVE-2020-4303
IBM WebSphere Application Server - Liberty 17.0.0.3 up to and including 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials dis...
Ibm Websphere Application Server
6.1
CVSSv3
CVE-2020-4304
IBM WebSphere Application Server - Liberty 17.0.0.3 up to and including 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials dis...
Ibm Websphere Application Server
4.3
CVSSv3
CVE-2020-4329
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 up to and including 20.0.0.4 could allow a remote, authenticated malicious user to obtain sensitive information, caused by improper parameter checking. This could be exploited to conduct spoofing attacks. IB...
Ibm Websphere Application Server
5.4
CVSSv3
CVE-2020-4421
IBM WebSphere Application Liberty 19.0.0.5 up to and including 20.0.0.4 could allow an authenticated user using openidconnect to spoof another users identify. IBM X-Force ID: 180084.
Ibm Websphere Application Server
7.5
CVSSv3
CVE-2016-2945
The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 up to and including 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote authenticated users to gain privileges via an external reference in a Swagger document.
Ibm Websphere Application Server 8.5.5.8
Ibm Websphere Application Server 8.5.5.9
NA
CVE-2013-0540
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 prior to 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.
Ibm Websphere Application Server 8.5.0.0
Ibm Websphere Application Server 8.5.0.1
5.9
CVSSv3
CVE-2018-1755
IBM WebSphere Application Server Liberty could allow a remote malicious user to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (JASPIC). This can happen when the Application Server is...
Ibm Websphere Application Server
6.3
CVSSv3
CVE-2019-4304
IBM WebSphere Application Server - Liberty could allow a remote malicious user to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950.
Ibm Websphere Application Server
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3380
CVE-2024-1694
local file inclusion
CVE-2024-5645
CVE-2024-24919
XSS
CVE-2024-36774
CVE-2024-21306
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »