IBM WebSphere Application Server
24 known vulnerabilities in IBM WebSphere Application Server, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-11711 CVSS 6.5 medium IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.
- CVE-2026-11710 CVSS 6.5 medium IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length…
- CVE-2026-11545 CVSS 3.7 low IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console…
- CVE-2026-11540 CVSS 5.3 medium IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through…
- CVE-2026-11539 CVSS 5.3 medium IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.
- CVE-2026-11538 CVSS 5.3 medium IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.
- CVE-2026-11537 CVSS 4.3 medium IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through…
- CVE-2026-16435 CVSS 5.9 medium IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or…
- CVE-2026-16190 CVSS 3.1 low IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.
- CVE-2026-16189 CVSS 4.8 medium IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative…
- CVE-2026-16188 CVSS 5.3 medium IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative…
- CVE-2026-16187 CVSS 6.5 medium IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by…
- CVE-2026-16186 CVSS 5.4 medium IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.
- CVE-2026-16185 CVSS 6.4 medium IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.
- CVE-2026-15887 CVSS 5.4 medium IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.
- CVE-2026-15634 CVSS 6.5 medium IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling…
- CVE-2026-15412 CVSS 6.5 medium IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct…
- CVE-2026-15396 CVSS 6.5 medium IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling…
- CVE-2026-9667 CVSS 5.3 medium IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote…
- CVE-2026-9327 CVSS 8.1 high IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify…
- CVE-2026-9176 CVSS 7.1 high IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker…
- CVE-2026-9338 CVSS 5.3 medium IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A…
- CVE-2026-9336 CVSS 7.5 high IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to…
- CVE-2026-8400 CVSS 9.8 critical IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB…