Ibm

Websphere Application Server

492 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 30.07.2026 14:09:23
  • Zuletzt bearbeitet 04.08.2026 15:23:30

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.

Medienbericht
  • EPSS 0.1%
  • Veröffentlicht 29.07.2026 18:19:36
  • Zuletzt bearbeitet 04.08.2026 14:10:12

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 29.07.2026 18:15:18
  • Zuletzt bearbeitet 04.08.2026 14:14:17

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

Medienbericht
  • EPSS 0.29%
  • Veröffentlicht 28.07.2026 20:52:17
  • Zuletzt bearbeitet 05.08.2026 16:26:56

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

Medienbericht
  • EPSS 0.18%
  • Veröffentlicht 28.07.2026 20:50:33
  • Zuletzt bearbeitet 05.08.2026 16:21:39

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.

Medienbericht
  • EPSS 0.52%
  • Veröffentlicht 28.07.2026 20:50:08
  • Zuletzt bearbeitet 05.08.2026 16:24:19

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

Medienbericht
  • EPSS 0.26%
  • Veröffentlicht 28.07.2026 20:37:32
  • Zuletzt bearbeitet 05.08.2026 16:00:48

IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.

Medienbericht
  • EPSS 0.38%
  • Veröffentlicht 28.07.2026 20:29:47
  • Zuletzt bearbeitet 05.08.2026 15:54:54

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.

Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 28.07.2026 20:29:09
  • Zuletzt bearbeitet 05.08.2026 15:53:53

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.

  • EPSS 0.26%
  • Veröffentlicht 28.07.2026 20:22:37
  • Zuletzt bearbeitet 05.08.2026 19:12:45

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.