Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm websphere application server 8.5.5.0 vulnerabilities and exploits
(subscribe to this query)
5.1
CVSSv2
CVE-2014-8890
IBM WebSphere Application Server Liberty Profile 8.5.x prior to 8.5.5.4 allows remote malicious users to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations.
Ibm Websphere Application Server 8.5.0.1
Ibm Websphere Application Server 8.5.0.0
Ibm Websphere Application Server 8.5.5.3
Ibm Websphere Application Server 8.5.5.2
Ibm Websphere Application Server 8.5.5.1
Ibm Websphere Application Server 8.5.5.0
Ibm Websphere Application Server 8.5.0.2
5
CVSSv2
CVE-2014-3021
IBM WebSphere Application Server (WAS) 7.0 prior to 7.0.0.35, 8.0 prior to 8.0.0.10, and 8.5 prior to 8.5.5.4 does not properly handle HTTP headers, which allows remote malicious users to obtain sensitive cookie and authentication data via an unspecified HTTP method.
Ibm Websphere Application Server 7.0.0.11
Ibm Websphere Application Server 7.0.0.12
Ibm Websphere Application Server 7.0.0.19
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 7.0.0.29
Ibm Websphere Application Server 7.0.0.3
Ibm Websphere Application Server 7.0.0.1
Ibm Websphere Application Server 7.0.0.10
Ibm Websphere Application Server 7.0.0.17
Ibm Websphere Application Server 7.0.0.18
Ibm Websphere Application Server 7.0.0.27
Ibm Websphere Application Server 7.0.0.28
Ibm Websphere Application Server 7.0.0.4
Ibm Websphere Application Server 7.0.0.5
Ibm Websphere Application Server 8.0.0.1
Ibm Websphere Application Server 8.0.0.2
Ibm Websphere Application Server 8.5.0.0
Ibm Websphere Application Server 8.5.0.1
Ibm Websphere Application Server 8.5.0.2
Ibm Websphere Application Server 7.0
Ibm Websphere Application Server 7.0.0.15
Ibm Websphere Application Server 7.0.0.16
3.5
CVSSv2
CVE-2014-4770
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x up to and including 6.1.0.47, 7.0 prior to 7.0.0.35, 8.0 prior to 8.0.0.10, and 8.5 prior to 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a craf...
Ibm Websphere Application Server 6.0.1.1
Ibm Websphere Application Server 6.0.1.11
Ibm Websphere Application Server 6.0.1.7
Ibm Websphere Application Server 6.0.1.9
Ibm Websphere Application Server 6.0.2.19
Ibm Websphere Application Server 6.0.2.2
Ibm Websphere Application Server 6.0.2.3
Ibm Websphere Application Server 6.0.2.30
Ibm Websphere Application Server 6.0.2.4
Ibm Websphere Application Server 6.0.2.41
Ibm Websphere Application Server 6.1.0
Ibm Websphere Application Server 6.1.0.0
Ibm Websphere Application Server 6.1.0.1
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 6.1.0.2
Ibm Websphere Application Server 6.1.0.31
Ibm Websphere Application Server 6.1.0.33
Ibm Websphere Application Server 6.1.0.47
Ibm Websphere Application Server 6.0.0.3
Ibm Websphere Application Server 6.0.1
Ibm Websphere Application Server 6.0.1.3
Ibm Websphere Application Server 6.0.1.5
6
CVSSv2
CVE-2014-4816
Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x up to and including 6.1.0.47, 7.0 prior to 7.0.0.35, 8.0 prior to 8.0.0.10, and 8.5 prior to 8.5.5.4 allows remote authenticated users to hijack the authent...
Ibm Websphere Application Server 6.0.1
Ibm Websphere Application Server 6.0.1.1
Ibm Websphere Application Server 6.0.1.5
Ibm Websphere Application Server 6.0.1.7
Ibm Websphere Application Server 6.0.1.9
Ibm Websphere Application Server 6.0.2.19
Ibm Websphere Application Server 6.0.2.2
Ibm Websphere Application Server 6.0.2.29
Ibm Websphere Application Server 6.0.2.3
Ibm Websphere Application Server 6.0.2.4
Ibm Websphere Application Server 6.0.2.41
Ibm Websphere Application Server 6.1.0
Ibm Websphere Application Server 6.1.0.0
Ibm Websphere Application Server 6.1.0.17
Ibm Websphere Application Server 6.1.0.19
Ibm Websphere Application Server 6.1.0.31
Ibm Websphere Application Server 6.1.0.33
Ibm Websphere Application Server 6.1.0.47
Ibm Websphere Application Server 6.1.0.5
Ibm Websphere Application Server 7.0.0.12
Ibm Websphere Application Server 7.0.0.13
Ibm Websphere Application Server 7.0.0.21
3.5
CVSSv2
CVE-2014-3075
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x up to and including 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file.
Ibm Business Process Manager 7.5.1.2
Ibm Business Process Manager 8.0.0.0
Ibm Websphere Application Server 7.2.0.1
Ibm Websphere Application Server 7.2.0.2
Ibm Business Process Manager 8.0.1.0
Ibm Business Process Manager 8.0.1.1
Ibm Business Process Manager 8.0.1.2
Ibm Websphere Application Server 7.2.0.3
Ibm Websphere Application Server 7.2.0.4
Ibm Business Process Manager 7.5.0.0
Ibm Business Process Manager 7.5.0.1
Ibm Business Process Manager 8.5.0.0
Ibm Business Process Manager 8.5.0.1
Ibm Websphere Application Server 7.2.0.5
Ibm Business Process Manager 7.5.1.0
Ibm Business Process Manager 7.5.1.1
Ibm Business Process Manager 8.5.5.0
Ibm Websphere Application Server 7.2
4
CVSSv2
CVE-2014-4758
IBM Business Process Manager (BPM) 7.5.x up to and including 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.
Ibm Business Process Manager 7.5.0.0
Ibm Business Process Manager 8.0.1.1
Ibm Business Process Manager 8.0.1.2
Ibm Websphere Application Server 7.2.0.3
Ibm Websphere Application Server 7.2.0.4
Ibm Business Process Manager 7.5.1.1
Ibm Business Process Manager 7.5.1.2
Ibm Business Process Manager 8.5.5.0
Ibm Websphere Application Server 7.2
Ibm Business Process Manager 8.0.0.0
Ibm Business Process Manager 8.0.1.0
Ibm Websphere Application Server 7.2.0.1
Ibm Websphere Application Server 7.2.0.2
Ibm Business Process Manager 7.5.0.1
Ibm Business Process Manager 7.5.1.0
Ibm Business Process Manager 8.5.0.0
Ibm Business Process Manager 8.5.0.1
Ibm Websphere Application Server 7.2.0.5
6.5
CVSSv2
CVE-2014-4767
IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x prior to 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
Ibm Websphere Application Server 8.5.0.1
Ibm Websphere Application Server 8.5.0.2
Ibm Websphere Application Server 8.5.0.0
Ibm Websphere Application Server 8.5.5.0
Ibm Websphere Application Server 8.5.5.1
Ibm Websphere Application Server 8.5.5.2
4.3
CVSSv2
CVE-2014-3022
IBM WebSphere Application Server (WAS) 7.0.x prior to 7.0.0.33, 8.0.x prior to 8.0.0.9, and 8.5.x prior to 8.5.5.3 allows remote malicious users to obtain sensitive information via a crafted URL that triggers an error condition.
Ibm Websphere Application Server 8.0.0.5
Ibm Websphere Application Server 8.0.0.6
Ibm Websphere Application Server 8.0.0.3
Ibm Websphere Application Server 8.0.0.4
Ibm Websphere Application Server 8.0.0.0
Ibm Websphere Application Server 8.0.0.7
Ibm Websphere Application Server 8.0.0.8
Ibm Websphere Application Server 8.0.0.1
Ibm Websphere Application Server 8.0.0.2
Ibm Websphere Application Server 8.5.5.0
Ibm Websphere Application Server 8.5.5.1
Ibm Websphere Application Server 8.5.5.2
Ibm Websphere Application Server 8.5.0.1
Ibm Websphere Application Server 8.5.0.2
Ibm Websphere Application Server 8.5.0.0
Ibm Websphere Application Server 7.0.0.13
Ibm Websphere Application Server 7.0.0.14
Ibm Websphere Application Server 7.0.0.21
Ibm Websphere Application Server 7.0.0.22
Ibm Websphere Application Server 7.0.0.11
Ibm Websphere Application Server 7.0.0.12
Ibm Websphere Application Server 7.0.0.19
5
CVSSv2
CVE-2014-3070
The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x prior to 8.0.0.10 and 8.5.x prior to 8.5.5.3 does not properly create accounts, which allows remote malicious users to bypass intended access restrictions via un...
Ibm Websphere Application Server 8.5.0.1
Ibm Websphere Application Server 8.5.0.2
Ibm Websphere Application Server 8.5.5.0
Ibm Websphere Application Server 8.5.5.1
Ibm Websphere Application Server 8.5.0.0
Ibm Websphere Application Server 8.5.5.2
Ibm Websphere Application Server 8.0.0.3
Ibm Websphere Application Server 8.0.0.4
Ibm Websphere Application Server 8.0.0.5
Ibm Websphere Application Server 8.0.0.6
Ibm Websphere Application Server 8.0.0.0
Ibm Websphere Application Server 8.0.0.1
Ibm Websphere Application Server 8.0.0.2
Ibm Websphere Application Server 8.0.0.9
Ibm Websphere Application Server 8.0.0.7
Ibm Websphere Application Server 8.0.0.8
5
CVSSv2
CVE-2014-3083
IBM WebSphere Application Server (WAS) 7.0.x prior to 7.0.0.35, 8.0.x prior to 8.0.0.10, and 8.5.x prior to 8.5.5.3 does not properly restrict resource access, which allows remote malicious users to obtain sensitive information via unspecified vectors.
Ibm Websphere Application Server 8.5.0.2
Ibm Websphere Application Server 8.5.5.0
Ibm Websphere Application Server 8.5.0.0
Ibm Websphere Application Server 8.5.0.1
Ibm Websphere Application Server 8.5.5.1
Ibm Websphere Application Server 8.5.5.2
Ibm Websphere Application Server 8.0.0.3
Ibm Websphere Application Server 8.0.0.4
Ibm Websphere Application Server 8.0.0.0
Ibm Websphere Application Server 8.0.0.8
Ibm Websphere Application Server 8.0.0.9
Ibm Websphere Application Server 8.0.0.1
Ibm Websphere Application Server 8.0.0.2
Ibm Websphere Application Server 8.0.0.5
Ibm Websphere Application Server 8.0.0.6
Ibm Websphere Application Server 8.0.0.7
Ibm Websphere Application Server 7.0.0.1
Ibm Websphere Application Server 7.0.0.10
Ibm Websphere Application Server 7.0.0.17
Ibm Websphere Application Server 7.0.0.18
Ibm Websphere Application Server 7.0.0.25
Ibm Websphere Application Server 7.0.0.27
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege escalation
CVE-2024-20696
CVE-2024-29829
CVE-2024-33999
CVE-2024-35646
physical
CVE-2024-24919
CVE-2024-31030
local users
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »