CVE-2026-11722
- EPSS 0.23%
- Veröffentlicht 18.09.2026 19:14:34
- Zuletzt bearbeitet 22.09.2026 19:32:25
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
CVE-2026-11549
- EPSS 0.31%
- Veröffentlicht 18.09.2026 19:06:17
- Zuletzt bearbeitet 22.09.2026 19:32:25
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.
CVE-2026-11548
- EPSS 0.23%
- Veröffentlicht 18.09.2026 19:05:48
- Zuletzt bearbeitet 22.09.2026 19:32:25
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
CVE-2026-14525
- EPSS 0.55%
- Veröffentlicht 13.08.2026 19:37:33
- Zuletzt bearbeitet 17.08.2026 18:10:40
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
CVE-2026-10571
- EPSS 0.53%
- Veröffentlicht 13.08.2026 19:30:52
- Zuletzt bearbeitet 17.08.2026 18:29:39
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the re...
CVE-2026-18499
- EPSS 0.27%
- Veröffentlicht 12.08.2026 16:25:07
- Zuletzt bearbeitet 17.08.2026 17:36:35
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.
CVE-2026-8400
- EPSS 0.48%
- Veröffentlicht 05.08.2026 16:17:09
- Zuletzt bearbeitet 10.08.2026 15:57:45
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation...
CVE-2026-10842
- EPSS 0.31%
- Veröffentlicht 30.07.2026 16:16:53
- Zuletzt bearbeitet 05.08.2026 14:15:05
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.
CVE-2026-11897
- EPSS 0.3%
- Veröffentlicht 30.07.2026 14:18:04
- Zuletzt bearbeitet 04.08.2026 15:26:57
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resourc...
CVE-2026-14980
- EPSS 0.24%
- Veröffentlicht 30.07.2026 14:09:23
- Zuletzt bearbeitet 04.08.2026 15:23:30
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.