Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm websphere application server liberty vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2020-4329
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 up to and including 20.0.0.4 could allow a remote, authenticated malicious user to obtain sensitive information, caused by improper parameter checking. This could be exploited to conduct spoofing attacks. IB...
Ibm Websphere Application Server
3.7
CVSSv3
CVE-2016-0378
IBM WebSphere Application Server (WAS) Liberty prior to 16.0.0.3, when the installation lacks a default error page, allows remote malicious users to obtain sensitive information by triggering an exception.
Ibm Websphere Application Server
3.7
CVSSv3
CVE-2016-2960
IBM WebSphere Application Server (WAS) 7.x prior to 7.0.0.43, 8.0.0.x prior to 8.0.0.13, 8.5.0.x prior to 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x prior to 9.0.0.1 allows remote malicious users to cause a denial of service via crafted S...
Ibm Websphere Application Server 8.5.5.2
Ibm Websphere Application Server 8.5.0.0
Ibm Websphere Application Server 8.0.0.9
Ibm Websphere Application Server 8.0.0.12
Ibm Websphere Application Server 8.0.0.11
Ibm Websphere Application Server 7.0.0.8
Ibm Websphere Application Server 7.0.0.7
Ibm Websphere Application Server 7.0.0.36
Ibm Websphere Application Server 7.0.0.35
Ibm Websphere Application Server 7.0.0.27
Ibm Websphere Application Server 7.0.0.25
Ibm Websphere Application Server 7.0.0.18
Ibm Websphere Application Server 7.0.0.17
Ibm Websphere Application Server 7.0.0.10
Ibm Websphere Application Server 7.0.0.1
Ibm Websphere Application Server 8.5.5.0
Ibm Websphere Application Server 8.5.5.1
Ibm Websphere Application Server 8.5.5.5
Ibm Websphere Application Server 8.5.5.4
Ibm Websphere Application Server 8.0.0.4
Ibm Websphere Application Server 8.0.0.3
Ibm Websphere Application Server 8.0.0.2
3.3
CVSSv3
CVE-2017-1681
IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local malicious user to obtain sensitive information, caused by improper handling of application requests, which could allow unauthorized access to read a file. IBM X-Force ID: 134003.
Ibm Liberty
3.1
CVSSv3
CVE-2016-0385
Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 prior to 7.0.0.43, 8.0 prior to 8.0.0.13, 8.5 prior to 8.5.5.10, 9.0 prior to 9.0.0.1, and Liberty prior to 16.0.0.3, when HttpSessionIdReuse is enabled, allows remote authenticated users to obtain sensitive informatio...
Ibm Websphere Application Server 8.5.5.2
Ibm Websphere Application Server 8.5.0.0
Ibm Websphere Application Server 8.0.0.9
Ibm Websphere Application Server 8.0.0.2
Ibm Websphere Application Server 8.0.0.12
Ibm Websphere Application Server 7.0.0.8
Ibm Websphere Application Server 7.0.0.7
Ibm Websphere Application Server 7.0.0.36
Ibm Websphere Application Server 7.0.0.35
Ibm Websphere Application Server 7.0.0.28
Ibm Websphere Application Server 7.0.0.27
Ibm Websphere Application Server 7.0.0.18
Ibm Websphere Application Server 7.0.0.17
Ibm Websphere Application Server 7.0.0.10
Ibm Websphere Application Server 7.0.0.1
Ibm Websphere Application Server 8.5.5.0
Ibm Websphere Application Server 8.5.5.1
Ibm Websphere Application Server 8.5.5.5
Ibm Websphere Application Server 8.5.5.4
Ibm Websphere Application Server 8.0.0.4
Ibm Websphere Application Server 8.0.0.3
Ibm Websphere Application Server 7.0.0.39
NA
CVE-2024-25026
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 up to and including 24.0.0.4 are vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the serve...
NA
CVE-2024-22329
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 up to and including 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to conduct the ...
NA
CVE-2024-22354
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 up to and including 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sens...
NA
CVE-2024-27268
IBM WebSphere Application Server Liberty 18.0.0.2 up to and including 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: ...
NA
CVE-2024-27270
IBM WebSphere Application Server Liberty 23.0.0.3 up to and including 24.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in a specially crafted URI. IBM X-Force ID: 284576.
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-3611
CVE-2024-4947
CVE-2024-32988
CVE-2020-35165
local file inclusion
CVE-2024-4980
bypass
malicious code
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »