Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
websphere application server vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2018-1683
IBM WebSphere Application Server Liberty could allow a remote malicious user to obtain sensitive information, caused by the failure to encrypt ORB communication. IBM X-Force ID: 145455.
Ibm Websphere Application Server
7.5
CVSSv3
CVE-2018-1553
IBM WebSphere Application Server Liberty before 18.0.0.2 could allow a remote malicious user to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature. IBM X-Force ID: 142890.
Ibm Websphere Application Server
7.5
CVSSv3
CVE-2018-1614
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote malicious user to obtain sensitive information. IBM X-Force ID: 144270.
Ibm Websphere Application Server 7.0
Ibm Websphere Application Server 8.0
Ibm Websphere Application Server 8.5
Ibm Websphere Application Server 9.0
7.5
CVSSv3
CVE-2017-1583
IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.13)could allow a remote malicious user to obtain sensitive information caused by improper error handling by MyFaces in JSF.
Ibm Liberty 3.13
7.5
CVSSv3
CVE-2016-8919
IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and cause the consumption of resources.
Ibm Websphere Application Server 9.0
Ibm Websphere Application Server 8.5.5
Ibm Websphere Application Server 8.0
Ibm Websphere Application Server 7.0
7.5
CVSSv3
CVE-2016-9879
An issue exists in Pivotal Spring Security prior to 3.2.10, 4.1.x prior to 4.1.4, and 4.2.x prior to 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a request, an at...
Vmware Spring Security 4.1.3
Vmware Spring Security 4.1.2
Vmware Spring Security 3.2.5
Vmware Spring Security 3.2.4
Vmware Spring Security 4.1.1
Vmware Spring Security 4.1.0
Vmware Spring Security 3.2.3
Vmware Spring Security 3.2.2
Vmware Spring Security 3.2.7
Vmware Spring Security 3.2.6
Vmware Spring Security 4.2.0
Vmware Spring Security 3.2.9
Vmware Spring Security 3.2.8
Vmware Spring Security 3.2.1
Vmware Spring Security 3.2.0
Ibm Websphere Application Server 8.5.5.6
Ibm Websphere Application Server 8.5.5.5
Ibm Websphere Application Server 8.5.5.4
Ibm Websphere Application Server 8.5.5.3
Ibm Websphere Application Server 8.5.5.2
Ibm Websphere Application Server 8.5.5.9
Ibm Websphere Application Server 8.5.5.1
7.5
CVSSv3
CVE-2016-5983
IBM WebSphere Application Server (WAS) 7.0 prior to 7.0.0.43, 8.0 prior to 8.0.0.13, 8.5 prior to 8.5.5.11, 9.0 prior to 9.0.0.2, and Liberty prior to 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.
Ibm Websphere Application Server 8.5.0.0
Ibm Websphere Application Server 8.5.5.9
Ibm Websphere Application Server 8.0.0.9
Ibm Websphere Application Server 8.0.0.8
Ibm Websphere Application Server 8.0.0.11
Ibm Websphere Application Server 8.0.0.10
Ibm Websphere Application Server 7.0.0.7
Ibm Websphere Application Server 7.0.0.6
Ibm Websphere Application Server 7.0.0.35
Ibm Websphere Application Server 7.0.0.34
Ibm Websphere Application Server 7.0.0.25
Ibm Websphere Application Server 7.0.0.24
Ibm Websphere Application Server 7.0.0.17
Ibm Websphere Application Server 7.0.0.16
Ibm Websphere Application Server 7.0.0.1
Ibm Websphere Application Server 7.0.0.0
Ibm Websphere Application Server 8.5.5.1
Ibm Websphere Application Server 8.5.5.2
Ibm Websphere Application Server 8.5.5.4
Ibm Websphere Application Server 8.0.0.3
Ibm Websphere Application Server 8.0.0.2
Ibm Websphere Application Server 8.0.0.12
1 Github repository
7.5
CVSSv3
CVE-2016-5986
IBM WebSphere Application Server (WAS) 7.x prior to 7.0.0.43, 8.0.x prior to 8.0.0.13, 8.5.x prior to 8.5.5.11, 9.0.x prior to 9.0.0.2, and Liberty prior to 16.0.0.3 mishandles responses, which allows remote malicious users to obtain sensitive information via unspecified vectors.
Ibm Websphere Application Server 8.5.0.2
Ibm Websphere Application Server 8.5.5.0
Ibm Websphere Application Server 8.5.5.5
Ibm Websphere Application Server 8.5.5.4
Ibm Websphere Application Server 8.0.0.4
Ibm Websphere Application Server 8.0.0.3
Ibm Websphere Application Server 8.0
Ibm Websphere Application Server 7.0.0.39
Ibm Websphere Application Server 7.0.0.38
Ibm Websphere Application Server 7.0.0.37
Ibm Websphere Application Server 7.0.0.3
Ibm Websphere Application Server 7.0.0.29
Ibm Websphere Application Server 7.0.0.21
Ibm Websphere Application Server 7.0.0.2
Ibm Websphere Application Server 7.0.0.12
Ibm Websphere Application Server 7.0.0.11
Ibm Websphere Application Server 8.5.5.1
Ibm Websphere Application Server 8.5.5.2
Ibm Websphere Application Server 8.5.0.0
Ibm Websphere Application Server 8.0.0.9
Ibm Websphere Application Server 8.0.0.2
Ibm Websphere Application Server 8.0.0.12
7.5
CVSSv3
CVE-2016-2945
The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 up to and including 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote authenticated users to gain privileges via an external reference in a Swagger document.
Ibm Websphere Application Server 8.5.5.8
Ibm Websphere Application Server 8.5.5.9
7.5
CVSSv3
CVE-2016-2923
IBM WebSphere Application Server (WAS) 8.5 up to and including 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified JAX-RS API cookie, which makes it easier for remote malicious users to obtain potentially s...
Ibm Websphere Application Server 8.5.5.9
Ibm Websphere Application Server 8.5.5.8
Ibm Websphere Application Server 8.5.5.1
Ibm Websphere Application Server 8.5.5.0
Ibm Websphere Application Server 8.5.5.3
Ibm Websphere Application Server 8.5.5.2
Ibm Websphere Application Server 8.5.5.7
Ibm Websphere Application Server 8.5.5.6
Ibm Websphere Application Server 8.5.5.5
Ibm Websphere Application Server 8.5.5.4
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »